23542300x800000000000000024653Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:35:58.691{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=754B364EE577CAE31528ADF09ABB5CFA,SHA256=D195FA48AF2B393353179D79EB9BA56DB3ED5353CEAB41DBD9593E7FCD8F7D18,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043599Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:35:58.667{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=133DE2AEC6C1925B5A20745BC9B24BB9,SHA256=1E72E044E4703E04277665685C6EDC49C7ACA985A0B3796724C2FEF0B4F52F0A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043601Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:35:59.685{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3B306622C0BD3E358A9366E674CA17C3,SHA256=89F0F8EB28947B487FA67B695FEBDEF554C4277CD092751B9F6CF3367A799525,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024654Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:35:59.691{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0CCF40759218BE898ADE05577604FCD2,SHA256=B4EE4FEB61AF2BC4EC63DDB5B38F6D89B91A6463DA452DC6A1DBE523C43A70EB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043600Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:35:56.843{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51570-false10.0.1.12-8000- 23542300x800000000000000024655Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:00.691{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B94ADB179597204694D35BFDF0D5A85C,SHA256=F05FFEC94A0D974C49C95D900A7612179083955533430FF87F6480D6C7563ECB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043602Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:00.716{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=197DA1B6FECCBCFE37EC07C73C3E426A,SHA256=7E5EAFAD576927CE2CC8A6FB4ACBAC4B6507A7A01AAA429375BBBB104F1B8B92,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024657Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:01.691{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D843188A94E9DD8B432B43A0AD5DC9F7,SHA256=CFEE0D9A4123A054FD5BF547D7C4B74DAF23C993F765D01EEE952815F92BADD7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043642Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.764{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B081736BA7AE366E20CC2357E416F1B,SHA256=72B2EBC4CEEB93D36A4D83D3808569CB167B26CBEA89F696597A98E55CDB7E2F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024656Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:35:58.975{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50834-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000043641Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043640Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043639Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043638Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043637Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043636Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043635Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043634Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043633Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043632Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043631Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043630Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043629Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043628Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2D00-00000000F001}1684C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043627Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2D00-00000000F001}1684C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043626Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043625Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043624Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043623Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043622Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043621Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043620Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043619Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043618Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043617Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043616Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043615Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043614Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043613Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043612Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043611Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043610Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043609Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043608Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043607Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043606Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043605Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043604Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043603Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:01.516{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000043643Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:02.799{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=367560B3D67AA373E090259A992354DB,SHA256=08FD5B1B87B9BE077ED350BFF1B09F647F7278DB206F9C721789158CA69EAA2D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024658Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:02.707{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2AB331FBE9B97D6FE68DCB05E1D8E2D6,SHA256=6952D89ADEF3F259CC416D29032F8B7ED8FE59D871C2536AB18152A5D133D80F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043646Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:03.830{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B9A7AC878152CE557362CDA6F66ECDA,SHA256=9F915B3239C570C774894204BC93068ACAB5E66FF93AE4634327B42EC6F89354,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024659Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:03.722{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=924D17AE635C027B0F0916692C7FE47E,SHA256=D1A368AAFBED9BE9388965E7595548E5B8B8AF085EBA103C3B4FBF12A6B08D02,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043645Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:03.299{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=055879BDA4F601FBB7B50EB470046C62,SHA256=4734740FFF25C6EA2B5BC77C0347E4FB282E6A26057863659595246974F1D8B4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043644Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:03.299{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F627EFE3B0E91B8313514819C808DBEB,SHA256=E75DAD34FEEA7C8C6613C770B613E28AAF17B3C34ABBF7F1629753A51E419BC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024660Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:04.722{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A273E7D1BAA6EE11237ACE4D970E8304,SHA256=E4C1A888C5203C7010B2C4EACF4D08EE87ADB7102368ADA0D7120C6C6C4A2577,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043655Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.845{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=904EE9A33E928972EE23D1CB5DAAF0C7,SHA256=7D17F50631D04ED6512EF3E1F55E6054EE2878C1936B535266BA914DDF757B95,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043654Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.566{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1944-6136-B508-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043653Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.563{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043652Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.563{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043651Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.563{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043650Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.563{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043649Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.563{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1944-6136-B508-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043648Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.562{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1944-6136-B508-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043647Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:04.562{323FE7D8-1944-6136-B508-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043675Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.866{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9EAAB3F4BC84633C67700B2F79FB0C99,SHA256=B884AA5C9C8BF895FB841C86EB313212C3A547BD074E0A801FEA3431033F77DE,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024689Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.832{FFF7FB96-1945-6136-2F06-00000000F101}6762640C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024688Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1945-6136-2F06-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024687Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024686Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024685Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024684Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024683Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024682Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024681Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024680Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024679Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024678Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1945-6136-2F06-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024677Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.629{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1945-6136-2F06-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024676Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.630{FFF7FB96-1945-6136-2F06-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024675Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.582{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024674Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:03.991{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50835-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000024673Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.144{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1945-6136-2E06-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024672Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024671Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024670Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024669Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024668Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024667Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024666Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024665Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024664Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024663Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1945-6136-2E06-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024662Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.113{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1945-6136-2E06-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024661Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.114{FFF7FB96-1945-6136-2E06-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043674Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1945-6136-B708-00000000F001}328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043673Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043672Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043671Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043670Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043669Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1945-6136-B708-00000000F001}328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043668Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.828{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1945-6136-B708-00000000F001}328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043667Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.829{323FE7D8-1945-6136-B708-00000000F001}328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043666Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.582{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=055879BDA4F601FBB7B50EB470046C62,SHA256=4734740FFF25C6EA2B5BC77C0347E4FB282E6A26057863659595246974F1D8B4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043665Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:02.609{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51571-false10.0.1.12-8000- 10341000x800000000000000043664Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.413{323FE7D8-1945-6136-B608-00000000F001}62402856C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043663Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1945-6136-B608-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043662Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043661Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043660Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043659Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043658Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1945-6136-B608-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043657Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.213{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1945-6136-B608-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043656Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.215{323FE7D8-1945-6136-B608-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024706Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.832{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7A420E2564C94992A09DC21F2D6742F1,SHA256=FD366E5073DAF5212724ECB6E03704ECD5A2C152C9F7D445C8E4FCF654602FA0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043677Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:06.881{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9DF6B4E9C736452B87BD94A384CAC0C6,SHA256=27417EC0035B9B1F946F2473B282640A839DBFFEED3022904F7886081AA30112,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043676Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:06.881{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B3BCA29C5592C1DA62709D096B684527,SHA256=04BDFB16D35D0E42DB2A4EE1ADCE704364064385CA83CE00EBF29F39C53BC5FA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024705Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1946-6136-3006-00000000F101}644C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024704Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024703Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024702Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024701Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024700Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024699Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024698Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024697Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024696Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024695Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1946-6136-3006-00000000F101}644C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024694Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.238{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1946-6136-3006-00000000F101}644C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024693Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.239{FFF7FB96-1946-6136-3006-00000000F101}644C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024692Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.175{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CB9406A8C39258BDDBF56E3E9B2E6BA0,SHA256=31A746E1C0BEC6AD648466DB2D5E10AEEC5EDA1CE88C6EC373B6533F33104188,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024691Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.175{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E17652426DD274E60B5BE6263660AA39,SHA256=3C69CA7D34626509B402BA893C73144734CD1761D355FD08DA5DA1EB4F2C046B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024690Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:06.019{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=344A1652EF7DD42995ACADC42760391F,SHA256=A494EDE3A9615172E550146CC09847ADAEDB58714A44AB1F075FF78C78D0474B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043680Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:07.912{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6CA4D61703F31112C7E53DF13BD2206E,SHA256=CAB1854F07F4D2728A4EACD459FF1DB70B4248D22AF0D9FBF618736626234F6B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024724Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.870{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CE860FFB39A057249845BEABDB2AC4B4,SHA256=7564FAF51D4B90F0921128C5E4A6DDE1F991F9FF9F7C2FD1B67B9C3872AD2088,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024723Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.865{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-087MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024722Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.644{FFF7FB96-1947-6136-3106-00000000F101}8003228C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024721Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1947-6136-3106-00000000F101}800C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024720Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024719Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024718Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024717Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024716Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024715Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024714Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024713Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024712Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024711Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1947-6136-3106-00000000F101}800C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024710Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.488{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1947-6136-3106-00000000F101}800C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024709Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.489{FFF7FB96-1947-6136-3106-00000000F101}800C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000024708Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:05.413{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50836-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 23542300x800000000000000024707Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:07.285{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CB9406A8C39258BDDBF56E3E9B2E6BA0,SHA256=31A746E1C0BEC6AD648466DB2D5E10AEEC5EDA1CE88C6EC373B6533F33104188,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043679Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.123{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51572-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000043678Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:05.123{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51572-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 10341000x800000000000000043699Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.946{323FE7D8-1948-6136-B908-00000000F001}17006936C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000043698Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.915{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9CAD327DC5BCCF1FE54335640B89D5A8,SHA256=8ACD4E8A56199B1F8BAB61583842D9E0B02B1BCEC11E568A6F0C49251BDDC384,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043697Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1948-6136-B908-00000000F001}1700C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043696Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043695Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043694Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043693Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043692Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1948-6136-B908-00000000F001}1700C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043691Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.746{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1948-6136-B908-00000000F001}1700C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043690Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.747{323FE7D8-1948-6136-B908-00000000F001}1700C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043689Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.300{323FE7D8-1948-6136-B808-00000000F001}58161168C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043688Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1948-6136-B808-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043687Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043686Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043685Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043684Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043683Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1948-6136-B808-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043682Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.080{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1948-6136-B808-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043681Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:08.082{323FE7D8-1948-6136-B808-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000024754Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.908{FFF7FB96-1948-6136-3306-00000000F101}8041628C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000024753Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.864{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-088MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024752Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1948-6136-3306-00000000F101}804C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024751Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024750Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024749Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024748Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024747Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024746Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024745Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024744Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024743Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024742Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1948-6136-3306-00000000F101}804C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024741Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.738{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1948-6136-3306-00000000F101}804C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024740Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.739{FFF7FB96-1948-6136-3306-00000000F101}804C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024739Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.722{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=39595E3F70E5980DEC0B486C130633D5,SHA256=BE749E600C10CA24CC02BB176D9817F41FCD24745802CC7376E550AE372EAF11,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024738Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.301{FFF7FB96-1948-6136-3206-00000000F101}7202476C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024737Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1948-6136-3206-00000000F101}720C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024736Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024735Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024734Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024733Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024732Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024731Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024730Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024729Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024728Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1948-6136-3206-00000000F101}720C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024727Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024726Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.113{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1948-6136-3206-00000000F101}720C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024725Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:08.115{FFF7FB96-1948-6136-3206-00000000F101}720C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043711Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.921{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=228A59506E1CFDCEE652C34FF870B2AA,SHA256=CC1193ED0047BC8DF2345037B0E8FA94E6501210F4533EDDE566321107117C5A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043710Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.673{323FE7D8-1949-6136-BA08-00000000F001}1003760C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043709Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1949-6136-BA08-00000000F001}100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043708Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043707Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043706Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043705Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043704Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1949-6136-BA08-00000000F001}100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043703Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1949-6136-BA08-00000000F001}100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043702Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.415{323FE7D8-1949-6136-BA08-00000000F001}100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000043701Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:07.852{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51573-false10.0.1.12-8000- 23542300x800000000000000043700Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:09.099{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3D9E3D04E6D7CD0828AC52621BC8B204,SHA256=A34BD213A6963408EA92C8CDD8E5A965DB43D114028668FEC91A0BCFB2E3CC86,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024769Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.739{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=18C1CB04D1B4EADEEEC00DFADFEEB3F7,SHA256=038C2346C98B80E2E715A27E51469C788C75E1440B229E340BD078BBD81A5A6F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024768Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1949-6136-3406-00000000F101}3608C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024767Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024766Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024765Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024764Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024763Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024762Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024761Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024760Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024759Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024758Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1949-6136-3406-00000000F101}3608C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024757Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.410{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1949-6136-3406-00000000F101}3608C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024756Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.411{FFF7FB96-1949-6136-3406-00000000F101}3608C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024755Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.079{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6A559B0D29ED6BFE6232CA1D3FB6E2CE,SHA256=943B84665195038190CB732EABA40368AC28546927572F7B1C7042694917F1B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043721Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.924{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4CC32CA7A7A6F62B70A22322505560FE,SHA256=BC0D69677A8B1841D65C69F6CA3C909ACD81C523309B599A0272EA39D1EDC844,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024770Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:10.082{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=352FA6FCBB22659C93D9E30F0BC69C9D,SHA256=11CA5BEA6CA937729EED4FBE561956FDB5E3EBB52960F648694EE33944D51E9F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043720Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.424{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3F97484470144DF335C9B02AC8FAF784,SHA256=D338F09EA6967C1632FC4497DCBCD69733144D398E86832E8477DDD5ACD3CE44,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043719Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-194A-6136-BB08-00000000F001}4668C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043718Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043717Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043716Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043715Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043714Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-194A-6136-BB08-00000000F001}4668C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043713Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.105{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-194A-6136-BB08-00000000F001}4668C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043712Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:10.106{323FE7D8-194A-6136-BB08-00000000F001}4668C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043722Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:11.954{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D6C839C5AA03EE2AB4EBF5C5F92538F4,SHA256=2051DEEEB7B3E1F1EF0D899C99EB967E9DDBD75BA9D2FEE8A6C9BD3C835FFC2D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024772Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:09.960{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50837-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024771Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:11.129{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2411B458B0E4DC04CE7941172BA4BFF2,SHA256=7E07CC07522B9BA688E3790127BE00227D4CF1A1C4540554EC5EC06C77B8223E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043723Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:12.969{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F8F9E55AFE0A79BF6ACBACD60B33751E,SHA256=F577B9625F1EB97D95CD203178AFAAC17705E79F1CED709EF46DE6A051934469,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024773Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:12.129{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B921942AABED6E34BBAB122087C506AF,SHA256=B58F824C96A99919F6DE8E503B7AC36722258219B581F14654B749C188752EBE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043724Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:13.987{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=73E676702638F9057796105C89971B02,SHA256=1EA749DD11C1C8F5720444BA1715E72BE4FFFB2FB40EC39B6EDF0838FA496D99,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024774Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:13.129{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A05CBFC5D82E8861CFC578E9F9D06625,SHA256=04A8CFB8919D0BB6FFCC4678403C165E2CB1F140623BAC0C34E9AF5583BB57DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024775Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:14.144{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2FB360C03B4AF580D53877AAC0274A9,SHA256=C1226AB67B6BE1284B1BC643B34F09702BE3AB2859AC025B5C663E31E16426CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024776Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:15.207{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=179218E96E7E2BAA2E8130E699B1E1BF,SHA256=8889935C7DDEC208411FF3D5D1F79D19F9CF53EC4D405FD67993579F5BA90210,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043726Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:13.601{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51574-false10.0.1.12-8000- 23542300x800000000000000043725Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:15.005{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8449FC1F5A57DEF74606349BBA477C44,SHA256=B47E0948E483FA35A3C7589596F40921F826E0D61391E33C25649491B5A10486,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024777Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:16.254{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B7904B16ECF306305B3FA6CFE7E1C7D4,SHA256=BECF9BE70855FF09B28D80DBBBF6BA5C41A27E7CD23F0018E394E03DBD267E62,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043727Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:16.020{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=955B41A513D223D15E581BC37F980FB1,SHA256=2A2800EAEDE82EF77A462B09D5EDA4578B81515140DBCC1AA773CDA33C20E854,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043728Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:17.051{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C5E6C061E9456E50DA2970382310F8D2,SHA256=C214448565E37217BA25385F0F576F196D8CC2A858BF20ADA8AEB6973F2DB2D1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024779Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:15.960{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50838-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024778Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:17.285{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5D77685CA0D70994DC4263B5E0C1FF4,SHA256=A764890797522FF49B48622727A5C4612C177870CB8BB97CCC0582E9B6EF6192,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043729Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:18.083{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15F8FCD0C6808C541144AA268EF2A982,SHA256=C6F0202CB4132E1080FF2B510951AF0B476F37E6FF3FC8B2EC7FCA5A3B0F83CB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024780Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:18.301{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C35917126C8C9EE852711ED11090B1C4,SHA256=B6509A5ED226127AF30BE504923DA423BF1F743BD08108D857BA39EFCD6CBD53,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024781Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:19.360{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD738DBF2871C70823C6C30B3109548D,SHA256=23F8FB4E375845E9B72522038DBD61B130F872C69E92740B6B42067BB03652D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043731Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:19.483{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-095MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043730Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:19.103{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B291F5C18BB31E0F79902D81D10425A6,SHA256=2300D2073F9D608A4D600B14EBE8E3764F4679DEF2C0D3D24A844603D8672821,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024782Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:20.392{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FED1E3E734C4B7415DC556ECBAFA0479,SHA256=4A82BA765C50F4FBE8D06A7B3FD550E4EBB95A50E32A5961C394A25A80D9622F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043736Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:18.828{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51575-false10.0.1.12-8000- 23542300x800000000000000043735Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:20.502{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-096MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043734Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:20.117{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AA4B333B3EEF24E1931BC2A33D5B8ACB,SHA256=1D3A0C83B0786A892232E7AC864A2A1A9075AB1E092C282D4195CEC2A16AE591,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043733Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:20.033{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=33120D223A941700840F61A3CAD468BF,SHA256=C91B6F45A47A5EEFC50BB145F9CF16A812A678E564AFC6219600B5A704C7691A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043732Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:20.033{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C65B2718071C296AC55EC4138C4FD0DB,SHA256=6535AF10D8EA82074DA141CD054D59A7C4640FC003E53B0527BE6A42698449E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024783Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:21.407{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC5C071F2C4F5C951E3411A1876A10A2,SHA256=DBE1F91ABFB328DA585D815182BBF56CFDE934FF2F5BA4D2492F87325788BBD5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043738Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:21.600{323FE7D8-022E-6136-0D00-00000000F001}9042288C:\Windows\system32\svchost.exe{323FE7D8-053A-6136-6302-00000000F001}4892C:\Windows\System32\rdpclip.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000043737Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:21.132{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=418971A3F2D91E6537E5267AA51C5461,SHA256=6DC0A5E8F43769816DFB735BAAA3FF45EF73BAEE90CB649D05533FFF04446EDA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043739Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:22.147{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9DA44D5ED5378E5F45A7F727F63EC8A,SHA256=EC420F5D7A203C6C2A7116B6E012BC5008C1B6B80C010E5433338A558A64EBFE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024785Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:21.020{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50839-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024784Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:22.407{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=82607416A02391A860AC45ACFF106E91,SHA256=1FD881A9FF66F785A026A30215F5F204957820E2F4991E3087666823CC954C25,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043740Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:23.179{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D860D55ACD1A60481EFA6391F89409A,SHA256=94DD64852BEE8ED07620A9127E4235C1722BE4F99D853B5E5234D06EEAE6E798,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024786Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:23.423{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B72052055E4E452979A1D4E5115D54EC,SHA256=F5710E5342E1B0ED969CA1F8F5EC2F01509FC90A9BD824870DE84D91482351D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024787Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:24.423{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=622C7029828F881C9A953D4272DF95B5,SHA256=F3C0C84152DEB7FB594AE7475449BB7B0D9552E23AFA8496628E44C40E72F070,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043741Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:24.214{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E8A38C7490D285872CA8A94F4AD9E722,SHA256=C46CE973F71606AA1E58703DB500F1B7F9BC866521CA63625EF2D84A5AADF855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024788Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:25.423{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7B898C0227797330B9032955B5968DF6,SHA256=612D8BDDC53B5672B91BF4D8BB2578C269CAE2583F47D69D95B847292534E090,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043742Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:25.229{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D931B1C1606BD5D77A8C3002EBB58CBD,SHA256=74F7EDD0F1054CF0CB066766C15E66AE08B5AA307E2699F8E3E4E95B406637F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024789Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:26.439{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=476149386743B6FCC5339B409EFC8D78,SHA256=E2FFA30A83D936807B968E7EEFF0679CEB0654AD71AEB9317E5921677EAC3E88,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043744Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:24.807{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51576-false10.0.1.12-8000- 23542300x800000000000000043743Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:26.244{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7369BC9FD931EDB8B9C2C474AEFB8154,SHA256=CBE4415D38D7B13BCBE6243D549833D2F695305397322F9E90398B7539393BA2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024790Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:27.470{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=28EE5BDC717E0E2C036A3CC2994E83FB,SHA256=F9293468E21DB42F6738F2DE2ABB2703201C4C2F4AC791A06E814698D245CBE3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043745Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:27.276{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C4CA0DFB994D206A4B6680D5C1B17E41,SHA256=3C2B10F186852A19540ED5F894039359DF9A35D7D800BBC17F85D57519965089,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024792Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:28.501{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA05153AA98FA38FA7EBB91345C87F66,SHA256=E32D40A4C9FBD77D95E6DBB3F21C8ABC525C2B4A05E987A21D17EDA10452460D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043746Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:28.311{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=92794DDC90399B39291C700BA58CA1DF,SHA256=BEAE4F52709982EF5CA7B639AF917F052083CEE4AA71906E24985D63A97CDBD8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024791Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:26.020{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50840-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024793Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:29.517{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9EDD4C4C5521919334781C47667BD02,SHA256=17728DCCF66612519A86200A40800490620F7979FEB96919AACC3B5AE5DEB0C7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043747Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:29.341{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB270EF50A6614961B1E441DF1424406,SHA256=D831DB30EFB035E3EEB3D630FF710D8553610789FF937BDEE98CD75F7F055448,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024794Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:30.532{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=88A63A0830C6E7E577D4AC829E1494C7,SHA256=462A8249B500DDF17812D2B21D527B11781836F78DC47045D36251AEFEA4E7C3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043749Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:30.341{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7DC2CA0D35E75C09C10379A873D675EA,SHA256=C977D840D1BDE9043FBD71EA59B46C12367FF1AA12F21883707F4403E7C6954E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043748Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:30.095{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024795Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:31.532{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=878A585F03ACEDB2935FE5A92B0D9058,SHA256=9193ADA1747D5EFFE9B31CCD631F0A1EBC7BF21B7160F4A9E7C57D4A3C56F909,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043751Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:29.667{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51577-false10.0.1.12-8089- 23542300x800000000000000043750Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:31.374{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4CCD1385BA1EB5E1E37E59D1AF77C55F,SHA256=42DE07BC79DB523CF7BDCE9DF825E83AAE64DF5CE8FDFA66C1D235FD0829C6CC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024796Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:32.548{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=60D97EC5997007213014AF546E4C68E0,SHA256=7EC0A6815114393EBA09FC51C4DD4830C0C07A30A17164C6B95301187137B994,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043753Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:30.820{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51578-false10.0.1.12-8000- 23542300x800000000000000043752Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:32.410{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F23CB72FFD21574B14D8BFD6B12C447D,SHA256=8F5FEBF85DEE99C89C5C4EDBACB7389D3FFCCCB5B03E331D01F1EB10C894B747,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024798Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:32.020{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50841-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024797Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:33.579{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D41F62FF644D0C6BBBC49CD4CFB6767E,SHA256=B22C1F1ECED8CFE40756C478417ECB4F418057ACF6BF2CD52B6D3FABE1B0AC07,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043754Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:33.425{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4ECE5A9BA7B3EF6F6965287458AD8E33,SHA256=1E88AC82D206CD74ADA8A7C223BF8CAF0BCF234E8AAE7259F50D1B2BEBFB31DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024799Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:34.595{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F10064B0579E493A82CB17C42F28D888,SHA256=D54ECE270136E34331C5FF32780BD99753580040383F0EFDC1B67E9625C01C18,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043755Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:34.426{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BA2F17105EA147C2034CF4B85D28E74,SHA256=898A7518581C4A75846F5B76DD7D2289E37F2E7E87FA041D7C5BFA98A0E81DE5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024800Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:35.611{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5036D6C6E421600F9178D3338BBB642,SHA256=F9F58E8CFA7B77BC32BC173A507604C0B1E671D71DC38E56F1C74840A3927FF0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043756Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:35.440{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE5F64F68337DBFEA8DA74BA0DC540A0,SHA256=06C16CDCE3C6BDDFA68FF5D6B76E518DCF4C6AB18DA6F00DE089EF47FB296C18,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024801Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:36.611{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2604D7A7843AB0716EF9059B5ADF821C,SHA256=C9534FCB5D815C0024FE58C92DABE263751E8AEB7D4D0F68815131C8DAAC8FE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043758Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:36.473{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D8C480385D63C9BE85467F84F00D189E,SHA256=455A8D05DB83DCEF71EBE4585829DE80BC24461C7FBEEF475033E1574F97531C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043757Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:36.172{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=33B9230349D431578A2B7A519E4CF8D0,SHA256=E6BAFCB28AE008FC1CE2056224D7D39E4A6F744EB48F4DC0AA9C140C3345733A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024802Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:37.611{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C29538F3BEA7D37F5B1C65187C6C6967,SHA256=5D898E0E812C5FB3E6E61ACFE006DB458E2D79AC6F8352A08760E01ADBF22C66,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043760Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:35.834{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51579-false10.0.1.12-8000- 23542300x800000000000000043759Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:37.476{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A0F5DBE454F675F0590EE621D326999,SHA256=9BC4F5531AD1A9DC58296073E47E2215342652CE792F9D29B4759C7AD2305099,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024803Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:38.631{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B0C4E16C25FC420E32F61B087FB012E,SHA256=8F58B05DB08B66255C077E00A6A8363FB55288F70FB11F1D313BDA584407A320,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043761Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:38.495{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=49CB5E186BB7FB6F4C5DC43DC3B557AE,SHA256=323AA382EA4BC56E6CDB4BCF0EB11BAD8630A597AC828514570B2034DBF01154,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024805Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:39.662{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D79EC160ACD5AA6A98825B129A127AAE,SHA256=5C002764097405C6673B0ADD50CE7C32F28F83D070A213598E066BC94FB5016F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043762Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:39.526{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=787206796E694B0F14A188A5E080347A,SHA256=A315A929313B517A90BC6A9A528AB3F514BEB53D15991B92091BE20919FB64AE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024804Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:38.020{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50842-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024806Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:40.662{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA39B45A1AC378DFEE466F6F9F78415C,SHA256=2858EF2462C2A4CD514D4DE4D035349528E3310B4066F02285E80B976870ADE4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043763Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:40.526{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=20BD3A4A31066C136D246AD2DF3136E2,SHA256=58235EB352E33893D73D1DF523513863D90F0C25460BE9EAE83D1D9AFAAB9EB9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024807Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:41.678{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B061282196C393D69185978D419DDF26,SHA256=B0B5938C20F38D0D4A115260F4BA2F6E56BB1C06C26CD77BA8A25FF1B4940884,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043764Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:41.556{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F83E220ADA8A5944DD841DC304B4D86,SHA256=57A23D746BEE882B1EB2C01AA06DBECEF1483B9C6A40AEA5F956D10BD18A71C6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043765Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:42.557{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C894FB12DA81BE02883379097EDD450C,SHA256=72C48E964D66A4E958C8519AA4D21F5B866C59C6775A0CC8B6B2259A262AAC53,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024808Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:42.678{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C2D880E92AF2ECE0560EE5EB0107A378,SHA256=8D08C60E3F1BB4F3E76F0D2AC8AFCF4DE890879F203069FE3293082FE06FF746,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043766Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:43.594{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E71517C459C25FAE12D43382809180E,SHA256=977CB228C32BEC24B8E71638F6A5B6953CF2DC77366A8A5815151F236D075E26,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024809Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:43.693{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A55E20907A0A1590F0B5293702BF6658,SHA256=AB9A045F2965903989874EB1E7301B3D35BE5B6888F1DD3E82A4CEB53288A382,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024810Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:44.756{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=993255FEC9B0A3CF0E7F0EEF2E0A0589,SHA256=29A26B1640371E66F2A6C4A238800844B2F26D633F0E4A75A920EC0E49A0481B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043768Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:44.624{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F82039DEE7A731CDD79BCDD37C32956C,SHA256=4560B09F04822523C282F4922468CD04E7C3B7E6B7095780664B4D47A4E9E324,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043767Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:41.803{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51580-false10.0.1.12-8000- 23542300x800000000000000024812Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:45.756{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E55B8BEB4C63AC5A9D50A6D4463D9B5D,SHA256=B2F1772ED7D9F83E99B1B65DF35277A7EEECF8E139282AFF5D9362B87932CD65,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043769Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:45.639{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D49B2C2E7F479CB28ADEAA949C3DF43D,SHA256=48DF10F055A1EE14DDCA096505A0D78A9739E47E7712569AC56B79CDEFA1D7C8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024811Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:43.946{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50843-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024813Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:46.787{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E1319D6C790A04B70BA67ED7D04C76B,SHA256=BF4890024173B8FE54A7354E00B78A601921E7EE7170796AE1C974245AD7880A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043770Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:46.654{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C95ECF002362985698AAFD8EEF4FBE94,SHA256=3C17D9E51EA2101F494F34F7E8F75CE8D3DFE41587233D4D49138A2420A85ABF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043771Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:47.671{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6599449A010151A001915DC26B70E180,SHA256=62B41A6FA8318B85F8DFA6C8C195509B342EE0B15F3FEEA2F048079FA82506C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024814Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:47.787{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9410AAE78E4F0E583EA36E06FE2C83D9,SHA256=B799155293547B032137649FE8274073B095F6090369E9FA690BD7BD5E18CF15,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043772Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:48.706{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=91AA956B3675980F183D93634774E3A6,SHA256=845BCBE3525B718F18A4CE86544F34C91CC3794D1C5A1112AB32646A68CE6418,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024815Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:48.818{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1B887B92A618FE89F602DA5DB833449,SHA256=F4FA0D337A4765A24DBCB3669C9A6ABE7717D3404FD4E33A1EC8EA365258A7F3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024816Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:49.850{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=87BE138D2C7F9BD0F68D82B021D1B44B,SHA256=B1F7DF3B134F12428436673F1048EB776D297F03091829F753C6C1307D428B5B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043774Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:49.737{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B69B9666B35E7E72B0DE2A2905E272B8,SHA256=331528C81BE577F79F359E13695CC8E363E5F0AA5EF92260E5FC24B724EE0A88,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043773Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:46.848{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51581-false10.0.1.12-8000- 23542300x800000000000000024817Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:50.881{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=23258E8C21300E9C9C9BD82832B4A93E,SHA256=9EF08E9E0C1BDDC6E8765576ECD23703CB08CAFF4D50AD8A0D6E8DFCEBEA0961,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043778Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:50.771{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9F28E2154AF29C5F1B719F2EB06E5905,SHA256=02643385AECEFAD92BE5FCAFBCDFFD14881253E0AAD781AEA443EB308C7E3D74,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043777Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:50.290{323FE7D8-022E-6136-0D00-00000000F001}9042288C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2D00-00000000F001}1684C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043776Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:50.290{323FE7D8-022E-6136-0D00-00000000F001}9042288C:\Windows\system32\svchost.exe{323FE7D8-0617-6136-F403-00000000F001}4476C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043775Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:50.290{323FE7D8-022E-6136-0D00-00000000F001}9042288C:\Windows\system32\svchost.exe{323FE7D8-0617-6136-F403-00000000F001}4476C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000043779Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:51.805{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C6A7DB0176795F1C94A66013BA56E85,SHA256=6F63E5F12039D7769B7DBBACA1917FD14D5BE363560926D544ECA9D66E5FDCCB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024820Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:51.896{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15C771B292127F4002752C3FE1484824,SHA256=5D1691C346F8F252331F6EA2AB8902BB95B8BD8D2D7D33BE1B0A1418B9CAA8F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024819Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:51.568{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=BADA7853F383D86C355A65703805952F,SHA256=6B1965BCC71C811D3A624F3F9F01C48B94F413416C5BBA3A07C861C0EA6CB9E3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024818Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:49.009{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50844-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000043780Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:52.835{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=52D8EF82BABB896A91F77100B61F0678,SHA256=70FF72E75CC5AD274FA50DBE2E1D1CA4B29718B3080632159F6FE37F195266B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024821Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:52.896{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=81F555550F13DC770C958A4036F2DF2E,SHA256=9BA3CC8C06996545D2BB05C2C9FD75BAF8188F950091D48BCE783148266E3A2C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043781Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:53.903{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC84FA0C6259C5D87FBF62E8185D7363,SHA256=8D4D6711ADEDBACA7C2957B27ECE8DE77D5304957F5F6DEB66FAAC70405C8629,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024822Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:53.912{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F464508913361A027D9A0C18208E8B0,SHA256=EE082615CFCB9DE26CBA80AEFA23C0D702F3FFB41209DE5F9D65FDC3E39ACD00,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043782Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:54.934{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A48DE880A21437DA45549E0E0ED427E,SHA256=E996A2F470290F73AF549B5B1C123EAE3C3B4F6043F1B2AA119A819ACEA7F9E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024824Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:54.959{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A318D3416DECE8F7A4D0F9A3772DE2FF,SHA256=8A651EBA3DB4E41804422AEFE4693D955DDA530D54C5F9764E8C45456E5131A2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024823Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:53.065{FFF7FB96-041E-6136-1500-00000000F101}1044C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcptruefalse10.0.1.15win-host-353.attackrange.local50845-false69.16.175.10hwcdn.net80http 23542300x800000000000000043785Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:55.968{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D47E114333F032A2E19EF5179ACF068,SHA256=71E0F1294C97AC69B99FA8E0835F4E262AEC364CCF757CE941ECC8EA9E976DA7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024825Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:55.959{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2AE28AA614270D56F439A9EC113C144,SHA256=205742FA70B6E2F0FBDFA7BD206FEFE2830FA0423F13FD35D29DC1612C55CCCB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043784Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:52.840{323FE7D8-023F-6136-2E00-00000000F001}1500C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-456.attackrange.local53domainfalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal51638- 354300x800000000000000043783Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:52.698{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51582-false10.0.1.12-8000- 23542300x800000000000000024827Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:56.959{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6AD0AC64E5AB185213C83340AB4B61AA,SHA256=5197C627831ECEAA6FD56D4CE0A5FCD1546A066FF8CD98AAF2375A83B36D8277,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043786Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:54.069{323FE7D8-023F-6136-2E00-00000000F001}1500C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-456.attackrange.local53domainfalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal58734- 354300x800000000000000024826Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:54.931{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50846-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024828Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:57.959{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D4773F5B8166FCF41CCFAF6283A4AAD,SHA256=30BF04D5A7DEF02B22C3C1E5DC14BDADDEA73C14CB9E62A2C24B58161ACBD0F6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043787Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:57.001{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F68668773BA7EE51E7C00BC244E5261,SHA256=B43B87A7E92C632CBF9647BEF4DE938396FFBCACCF3C5084DC70A30D0580640B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043788Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:58.016{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C08E3869A439227EEAF12EA4AC96183,SHA256=D3B38624F746F3D17C7E3A07990EEA6AA75902FF0C3E7E8556BB6B29C1C67FF6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043789Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:59.031{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B188299D59E0F60BA7ABE3F62EDCCB94,SHA256=2F4CB90F9ED78A0213ECB6BDC350D9558DA82F605E733A87FF7F0F8B5CD8D487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024829Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:36:59.045{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9649278FAEBCE6ADBE2551F1C8FCF6B4,SHA256=738EE5508BAFE068C72907A7B1BBB46A5C1F7E45D34A9E6FE3932411549AE90E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024830Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:00.045{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C6F774A89CAA6A5874CAD82E9F1983AE,SHA256=4269C6DBB28678481C4EE8F0880886E3094C9B31D49826F5D9DCF7D91B0091B1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043791Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:36:57.710{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51583-false10.0.1.12-8000- 23542300x800000000000000043790Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:00.046{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F22898BA185219D7153C4F0A98F963D3,SHA256=AEBDC35B4DFE2BFE451EC678468FC722B3BB643F05883566DA2691D238107E9F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024832Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:00.001{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50847-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024831Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:01.077{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A50B1E29A924C35750E9EDB47FBF3DE0,SHA256=A4FEA61B5F848BCEB4C897A27038A096EC937F3DC56EB61D26C5B6BEA77FF03C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043792Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:01.082{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=341AEAF959E36ABEC94018B6F18D0CCE,SHA256=DB6157B3C106105D5E7E053785D3EF82ECC0616EB9FB589C9232B808CE9E8214,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024833Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:02.123{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B71593DFF9C72FC52386608F65B9AD8,SHA256=351951EBE8ABDBEE5AA7A34E9889C5DB4D996C29F237AA5DA647E72ABABFD14B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043793Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:02.097{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05F05F98D018B4B3C450A30EAE17D848,SHA256=E379008B89269912D22F83EF49B10FA5D5A02E4D0A0144DFAF4950001958F0A9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024834Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:03.139{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=119B84A6AAF1E3AEA854B1B07348586D,SHA256=15CFC8DACD0E8CFB030E8F786A25E09E0D9F0D3AB7CF6037D77172ABBC54B40E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043794Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:03.112{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A863556C7E11A6F27C5DCDB8AE470B6,SHA256=3D837FCDB6555B5F1DE0B30E35DFD57C883DBD9FBC5380C8FEA8CEB20B5F335F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024835Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:04.155{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B26DF9FD853E0FEC75104E10052CC7D,SHA256=8DD63C80CCB77D1D9595930ADA0FDA109B7280F441F1DB28CBABD544A53D55D6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043805Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.611{323FE7D8-1980-6136-BC08-00000000F001}4932364C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000043804Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:02.837{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51584-false10.0.1.12-8000- 10341000x800000000000000043803Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1980-6136-BC08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043802Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043801Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043800Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043799Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043798Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1980-6136-BC08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043797Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.411{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1980-6136-BC08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043796Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.412{323FE7D8-1980-6136-BC08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043795Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:04.142{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB95AE3A0ABD0E6B0A31D364187F7DA1,SHA256=5D33043047565845D77F9CD637D45417EF123BEE46E57023A6BE309F51B47D82,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043824Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.762{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1981-6136-BE08-00000000F001}3340C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043823Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.760{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043822Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.760{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043821Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.760{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043820Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.759{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043819Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.759{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1981-6136-BE08-00000000F001}3340C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043818Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.759{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1981-6136-BE08-00000000F001}3340C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043817Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.758{323FE7D8-1981-6136-BE08-00000000F001}3340C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043816Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.426{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2CB50FB5EE8B83691D240C435ED24149,SHA256=349016206128673D0673C9F66BC345E7059582842290AB9A87B76979073128B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043815Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.426{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=33120D223A941700840F61A3CAD468BF,SHA256=C91B6F45A47A5EEFC50BB145F9CF16A812A678E564AFC6219600B5A704C7691A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043814Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.164{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44D4BAE7DFF7D3F1A076C37D404B6C25,SHA256=126B23D7D9C249E5DE9CA2FAA6584167657C5AE8ABDE116EDBB52F8E456203C8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024864Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.985{FFF7FB96-1981-6136-3606-00000000F101}33441120C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024863Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1981-6136-3606-00000000F101}3344C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024862Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024861Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024860Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024859Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024858Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024857Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024856Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024855Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024854Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024853Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1981-6136-3606-00000000F101}3344C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024852Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.795{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1981-6136-3606-00000000F101}3344C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024851Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.796{FFF7FB96-1981-6136-3606-00000000F101}3344C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024850Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.608{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024849Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.170{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F073FFBB6C39F7231BB14E556EE9F5A5,SHA256=EE2A392CD69568A178693A1BC714AC67F71BC026A5E8BC0E816BE1BB0C7028DA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024848Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1981-6136-3506-00000000F101}1876C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024847Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024846Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024845Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024844Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024843Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024842Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024841Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024840Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024839Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024838Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1981-6136-3506-00000000F101}1876C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024837Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.123{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1981-6136-3506-00000000F101}1876C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024836Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.124{FFF7FB96-1981-6136-3506-00000000F101}1876C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043813Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1981-6136-BD08-00000000F001}696C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043812Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043811Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043810Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043809Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043808Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1981-6136-BD08-00000000F001}696C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043807Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.095{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1981-6136-BD08-00000000F001}696C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043806Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.096{323FE7D8-1981-6136-BD08-00000000F001}696C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000024882Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.439{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50849-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000024881Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:05.033{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50848-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000024880Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1982-6136-3706-00000000F101}2384C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024879Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024878Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024877Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024876Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024875Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024874Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024873Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024872Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024871Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024870Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1982-6136-3706-00000000F101}2384C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024869Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.467{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1982-6136-3706-00000000F101}2384C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024868Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.468{FFF7FB96-1982-6136-3706-00000000F101}2384C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024867Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.170{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2035A6B44E075FC397BC92508F6F3DE2,SHA256=D891C5C9AC6B832B351F6BE11770FFD4732C0554C03FE864F55514304BD500F1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043826Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:06.561{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2CB50FB5EE8B83691D240C435ED24149,SHA256=349016206128673D0673C9F66BC345E7059582842290AB9A87B76979073128B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043825Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:06.179{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16D705C8900C62E9ED2C723E5D96AA2A,SHA256=3AF62350EB242C8D018AEBC945D98D99190036FA56593D6614F344D9AC293D43,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024866Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.123{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=042E086AF62B4D1EAF80D7027AE45849,SHA256=377E5CAEAA71E5EE87192C9B7C7D261E8319DB9D40DCFCFACF2400E9C1005879,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024865Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:06.123{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DA2A1ECEADA3E2200AD7EF0D5786F9CE,SHA256=9F3BA2451A6336944B2750CCD6B8B76628C1C0BE2D648FBB29E7C829CAAE7157,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024898Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.545{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=042E086AF62B4D1EAF80D7027AE45849,SHA256=377E5CAEAA71E5EE87192C9B7C7D261E8319DB9D40DCFCFACF2400E9C1005879,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024897Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.498{FFF7FB96-1983-6136-3806-00000000F101}32122956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024896Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1983-6136-3806-00000000F101}3212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024895Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024894Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024893Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024892Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024891Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024890Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024889Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024888Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024887Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024886Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1983-6136-3806-00000000F101}3212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024885Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.358{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1983-6136-3806-00000000F101}3212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024884Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.359{FFF7FB96-1983-6136-3806-00000000F101}3212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024883Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:07.202{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0EF2BAF8894F9B97D09D894426A2DE4,SHA256=37D6B4D00DF59473CED4C399513F4125C62D96B9122D4CD800C244DEA9F96CB9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043829Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.137{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51585-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000043828Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:05.136{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51585-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 23542300x800000000000000043827Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:07.194{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=68AF141716D8E3FAD8C609902A3DE5DE,SHA256=90DBDC1132227CFBB2001BA115471CAA8F99FF3860E895A85BFADE4263313575,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024927Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.858{FFF7FB96-1984-6136-3A06-00000000F101}25643016C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000024926Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.717{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C353377C59B4831CE928CAFE7F777043,SHA256=21EE2E16B2A8646FDD9127E9B5BB4363673A73B771C2316A666BAB68579D219F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024925Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1984-6136-3A06-00000000F101}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024924Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024923Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024922Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024921Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024920Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024919Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024918Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024917Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024916Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024915Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1984-6136-3A06-00000000F101}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024914Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1984-6136-3A06-00000000F101}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024913Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.702{FFF7FB96-1984-6136-3A06-00000000F101}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043848Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.908{323FE7D8-1984-6136-C008-00000000F001}63161828C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043847Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1984-6136-C008-00000000F001}6316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043846Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043845Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043844Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043843Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043842Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1984-6136-C008-00000000F001}6316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043841Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.739{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1984-6136-C008-00000000F001}6316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043840Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.740{323FE7D8-1984-6136-C008-00000000F001}6316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043839Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.293{323FE7D8-1984-6136-BF08-00000000F001}38405384C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000043838Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.208{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ABE1E3933AC520BFE7584A1EA5D27B1E,SHA256=67DBEEB051B12455FACCE7B8F6239B8B3FE6F629DFD1BBAC2069B9D6773260B1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024912Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.170{FFF7FB96-1984-6136-3906-00000000F101}7001704C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024911Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1984-6136-3906-00000000F101}700C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024910Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024909Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024908Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024907Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024906Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024905Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024904Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024903Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024902Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024901Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1984-6136-3906-00000000F101}700C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024900Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1984-6136-3906-00000000F101}700C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024899Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:08.030{FFF7FB96-1984-6136-3906-00000000F101}700C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043837Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1984-6136-BF08-00000000F001}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043836Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043835Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043834Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043833Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043832Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1984-6136-BF08-00000000F001}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043831Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.077{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1984-6136-BF08-00000000F001}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043830Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.078{323FE7D8-1984-6136-BF08-00000000F001}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000043859Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.576{323FE7D8-1985-6136-C108-00000000F001}58165032C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043858Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1985-6136-C108-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043857Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043856Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043855Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043854Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043853Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1985-6136-C108-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043852Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.423{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1985-6136-C108-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043851Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.424{323FE7D8-1985-6136-C108-00000000F001}5816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043850Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.223{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D3274DB0EDAD92A9075247E938CA1D6,SHA256=E25A6BADBDE899B418CDD09D9BB82A5F5D0D229D8BE077FB63CBD37E25F28756,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024942Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.393{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-088MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000024941Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1985-6136-3B06-00000000F101}2540C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024940Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024939Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024938Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024937Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024936Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024935Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024934Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024933Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024932Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024931Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1985-6136-3B06-00000000F101}2540C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000024930Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1985-6136-3B06-00000000F101}2540C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000024929Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.375{FFF7FB96-1985-6136-3B06-00000000F101}2540C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000024928Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:09.062{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E6BF644B31CBDA3FCE772381BBB3DB0E,SHA256=E5C76F2DDB3C07854C366116FF015A093FFE64979316D15F302AF5CC5CA79FAE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043849Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:09.092{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=57D2B1669CE2BD301C22AE2426A770F9,SHA256=A74A17EFF0D49A3A5D109B0340560C8D37D98C6A4FFEF816A856C06310DADC81,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043870Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:08.649{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51586-false10.0.1.12-8000- 23542300x800000000000000043869Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.423{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2FB46BD8DAAEE5F33D2585C26B8BB551,SHA256=CE401264C437BFCE5E8224F59FEE55EAA3D300EC0FA2C982BCC649FD1BC4F4F3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043868Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.241{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=946E8D9ADCD041518562DE13C6F58055,SHA256=BEC1207FD1DE2E613C0EDBC2043FC4FB346D5FAA27CAB951F1377DDA14BB7E7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024945Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:10.395{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CE2B2328946CD4E6B7E45083D251DB7A,SHA256=AD0FB4AC34E84525B4215D3E8DA77003B9924B3CB1C43B962336F7A3A0442A1C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024944Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:10.392{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-089MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024943Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:10.219{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F616057449869B61A1AF23C7B659CC15,SHA256=DE530DC5C667DAFB868B836D43F41DE040AE3059AEB1DC4A339FBF04182680C3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043867Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1986-6136-C208-00000000F001}6936C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043866Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043865Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043864Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043863Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043862Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1986-6136-C208-00000000F001}6936C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043861Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1986-6136-C208-00000000F001}6936C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043860Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:10.092{323FE7D8-1986-6136-C208-00000000F001}6936C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000024947Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:10.050{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50850-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024946Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:11.220{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C0A624BEC899984849329FC43771E944,SHA256=AE63E9396660E7844F5B68377E6AC86B8E015031169DDCB7786EAB433A9FEE27,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043871Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:11.257{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F9B85047EA67FA21B2EC570FAC61A70,SHA256=A6FAE770A4D779BB65B7A9C736FB156E2DDBCFC1CE5300D4B9CB8DF7C6A636A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043872Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:12.277{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18DD34C424717F6DEFCB9E6CDAAFF94A,SHA256=B9B6F2C9280E4240FAA96EA36BB341AF013E9894E1A4CFD7A8A9DB237DEEF40F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024948Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:12.236{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D33A11B3FB29BF12744645C9B055014,SHA256=87C996B3F922FA6682BA757C1899B217EBA0A3AA6DEF736890B9305007A3860F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043873Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:13.278{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=93BEC05CC7D9A182A71CB373F9F4FD1F,SHA256=3821A76CEC8ED64F264D1C67B23E484C4819B597C5FF1BA72E7386BDDDF18484,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024949Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:13.251{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1CD1C5F4D6BC36ED203CE8A918097446,SHA256=211334653BAE8319F4164C7FAE14F1DF1775E251CD20D220F493B27D19AE0E51,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043874Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:14.294{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C3F315D77E350D4DBC7DB037ACEE2FC2,SHA256=60A62CE117C87873A884870EA080A0102A5C3E482A57CCBDF9A541DEB3F93C12,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024950Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:14.251{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=012E09E259C258504A162FB12997A1B2,SHA256=304E4AECCC9D5E011BEA2B5038F3F83191FF9BDDD73109C85B3BA3FB5F4C8906,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024951Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:15.251{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5EFF6007FC309B4EB1C84F1389C90517,SHA256=51410FC11F26958EF67EC95813442E5AEAAE791BAEE05BA71E25F83026A67D5F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043876Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:13.803{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51587-false10.0.1.12-8000- 23542300x800000000000000043875Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:15.308{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F46259948B36ABAFA9083B8DFCF70A08,SHA256=4B59DF78562801E8A85C432A5AD0B584707D785181706F865ADFC61CB881B030,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043877Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:16.324{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=176E307CCFBD9C44A434A267376F34DC,SHA256=C23CE5F1FE6D177376561E7109243CA40E3B4A3EF6A5647B5CAB7A1546C4CD9F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024952Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:16.267{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=48D416D134B7EFCC5D7DA2A20979C524,SHA256=904B5DB31DFCABE4119A1B4C7187D423E880AE4033D9C1901828B75A75E3D84A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043878Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:17.340{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=440024691999EBED6D19B1ECE7537FC5,SHA256=E57E829365A7FAEEFEDC4CDEAA56DA01F8AC3EA6BBE0E7766A848A888F2A3FED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024953Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:17.283{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=77C08B937EC20DA5FF272DD478F0F9D6,SHA256=B921A5119BBE0A6B500009AA3A1A6AB873824FF85135626845BF87809A498C5A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043879Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:18.357{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FF68ECB59443F43840DD2AAB159DA244,SHA256=CFA3830C452FFE4ACAD01C06501FF158C4A0EB924362EFBBE1D8C82208CB7992,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024955Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:18.283{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1DA3F2A8D461FDFB3251C97D1CBB3EEF,SHA256=2A15036FB4CB73004140EB436B6DA50BCD52CECD5CB6E867A746DC84EA2CA8E3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024954Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:16.004{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50851-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024956Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:19.293{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF2030572B9FF0441E475A34219FB734,SHA256=BD78F22CC683936C44C8B2265EE01ED13C52D06F3BDA1E21150748FC75B09EE5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043880Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:19.376{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5F977B6AF31FD4927ABFDDAB1D723E4,SHA256=D48DA938631548F3DB8695DB5C46653C4926BCFB9126432060EC5E81AABA506E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024957Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:20.298{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8837E18FC05ABEAC75B412E18935B8A,SHA256=3BC6FF6317A6FA0E6AAAC01072BA1EC1FF1A5983B2AB176DA3FEC7ED37660624,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043881Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:20.391{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=469EA52818767060CAC6DEA184D5BECA,SHA256=2534C34817A9E6E5271094B033E9F07B02910BFCA47DF58C0E8FBC9B12DA8FE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024958Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:21.309{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=132BB09B211C8655816D6616EB221B69,SHA256=809FF86DD3DB40DAC5F78FE1B22DD3F91CCD7733BAF88AFF3F251506E94BD11D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043884Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:19.670{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51588-false10.0.1.12-8000- 23542300x800000000000000043883Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:21.392{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0ED8ECE01BC7595C2C4783DEC5EC3F71,SHA256=59D31973A1017CF2863139835F343A86D279C871D574A42522829B1A86DC5E0B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043882Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:21.025{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-096MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024959Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:22.309{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A70172537A4595D05B9F5FE24E5D81AC,SHA256=BCE66DB5E6D94ECB7907EC16088C4FEC7B4ABD6EDC1CF2858A35673A4BDC7A3F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043886Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:22.392{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=644982BFFD2D54ACDDF5A0AA1DBD4BF6,SHA256=58DD4AAF43B576D80071B1346461D4B7BF5666760957B564EF60214C3D2B931C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043885Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:22.024{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-097MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024960Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:23.324{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D6C25F055E83F7F966AA55CDED7C943D,SHA256=B92281ED8F65EAC8850362C9274F8CF1B18F8757BA4A603EAFB59EE076069FA6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043887Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:23.423{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84B62AA73FC68158BE06EF3B3E4CE57F,SHA256=8987AA4CF263E7A7CAC28575329426F419D0CED585335E9EBD46C35400C4906E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043888Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:24.457{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DBE806F6DF993D91B518AA87FFB0C7E,SHA256=13BD3D00CB90DDA092D6881C661D51C44C3EAABB1FDFA994007D9D637A831BF3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024962Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:24.340{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE643B15CC98591FADB96034E5063E46,SHA256=99C45A36A2C490F3962A8A671AA5B3A9878012EE75889F6A9799E185A00B70C5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024961Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:21.999{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50852-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024963Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:25.356{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5BE6F98E70D5D418357F35185D2A755D,SHA256=AAF0FF7978AE6C247B50CED2F286E30B28CA1F819119F2B8493FE5EC00486549,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043889Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:25.475{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B622B98F0780A079DF188AEED7525886,SHA256=97FB520325E0013D029734D483A7962A2BCB6182A61BD40583F43A132E53FD0B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024964Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:26.356{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D8493F4B93D78485CF42EF9754EE8CE,SHA256=077E66626BAEEE44AEF4183F9E4D7B2CCF0E81EBD7BC11F69AA84F15704116CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043890Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:26.490{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D882FFC6FBC0D88A3CBE1BD5FADF110D,SHA256=85456ADC7F07129CA0F6169F987D1265C2714B8EDAD42B1713BBF986BBD02362,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043892Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:27.504{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=83ED232A8A6BAB249A82EF7901C99D10,SHA256=2D972D1F3193352B720DEE052ED21E77F50F20D7A5074ADE583E3987F5E9BE22,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024965Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:27.371{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D326F78CF942952135A481D65637DDE6,SHA256=16B5539FB7EC6826E4F4E536E6823CED3748F038E7B45161DB8E0D96BD39903E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043891Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:24.785{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51589-false10.0.1.12-8000- 23542300x800000000000000043895Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:28.519{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F7B781B87354E903796343D3BBF9918B,SHA256=34E25552C0D4684C313D8A22080953A5D388816FFB4A7622BA6EBEFB4999017F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024966Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:28.371{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CE091B1CF01674F298C049D1B6064B4E,SHA256=EB34BF4FB046A8446759C9A9471C43220C5926F32F49624A0517F8BA29474232,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043894Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:28.488{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2BFAE9961998D13F4D29896EACED9A72,SHA256=586F0A6C42F50DD55B85DEF5052B3B6372D10212C05DE56FA7366F0A606890F9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043893Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:28.488{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F133DF12B8EE5EC619F149266248C0B5,SHA256=63E826F8B047834DEED81C1A3645FC8287C734546EFAF357AE3D80CF97E683C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043896Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:29.553{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=30DA489047A0C84991EF3C6F260BB6F2,SHA256=2684E0D05302345AA6A6D8ECC8A4B57E4F63B777B91AA432365AC2EA2B7AB9AB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024968Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:29.371{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5216EE02D84AEE20D3826CA12D130D1,SHA256=ADCE8D84200B7BA21951B8A459079E8CF105C97601D5DF29EB22F7C52E6B2B38,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024967Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:27.030{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50853-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024969Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:30.387{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8586E96D5D7B25E98E1EC756D8F8E232,SHA256=E5C274D3460123FA1AA063C5D40CE486ED5E2262F51586050C93BF5C00DD6AD8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043898Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:30.586{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09158CC8D81E3B2C4823C4BD9849C88C,SHA256=6C1BE7EA1AD9E3516646DFABB783E94F8D6B368C2E2E58EF8683361E6B05C80C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043897Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:30.118{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043899Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:31.617{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=20F709401ADAB7DDC4EB39F564FCBB6D,SHA256=DD7EBFBD8E0F737A35B645CB367C530D24568C584C96D4B08900052C0E1367D1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024970Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:31.387{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DD33FDAE9660011A1C48093D41BEB6D,SHA256=41BB90C6518A0B667E3D7D9E5DF1475D89915DF4E52D9045C64EF1E61DCAE0FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043901Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:32.653{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=68587E8C2BD040CC80521C2A84B6E58F,SHA256=6D670E7814F35323E059B0042B58E35636B0501A159DEB0C816370A4470B1478,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024971Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:32.387{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=264F73542A6E8BB342E28A9BF4337199,SHA256=3BAA9ADC9408330955C0B6E6986F4E47BE07226970AAB230935315BE03A7C731,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043900Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:29.697{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51590-false10.0.1.12-8089- 10341000x800000000000000043904Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:33.769{323FE7D8-022C-6136-0B00-00000000F001}624812C:\Windows\system32\lsass.exe{323FE7D8-022A-6136-0100-00000000F001}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96ef2|C:\Windows\system32\kerberos.DLL+793e4|C:\Windows\system32\kerberos.DLL+1443f|C:\Windows\system32\lsasrv.dll+2d211|C:\Windows\system32\lsasrv.dll+2b3d4|C:\Windows\system32\lsasrv.dll+30929|C:\Windows\system32\lsasrv.dll+2e287|C:\Windows\system32\lsasrv.dll+2d211|C:\Windows\system32\lsasrv.dll+15ded|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 23542300x800000000000000043903Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:33.685{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=89FA119C924D5CAFC695C385EF9991FD,SHA256=9E7CA7F449A6721BE1A09BB583350A0040B25F2AE1E1CB51D30C3B1A10C8FC92,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024972Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:33.387{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=664C2DC63233D8938D0A2BC8E19D2AFC,SHA256=E1066DAB4017891AFB77BD5598BB9238CBECEDE38E73FDF72C90F358C158A851,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043902Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:30.665{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51591-false10.0.1.12-8000- 23542300x800000000000000043907Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:34.784{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C82AB87BEE153B176860E32796E221CA,SHA256=B707E4B33F2A8C501A4704FC2E572F3327B1B9FBDEB667CAC077BA0EC404B8C5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043906Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:34.784{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2BFAE9961998D13F4D29896EACED9A72,SHA256=586F0A6C42F50DD55B85DEF5052B3B6372D10212C05DE56FA7366F0A606890F9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043905Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:34.715{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A70027C90F9F30599C8E2124E34E59A8,SHA256=B96FBCC19307565A049CD7CF8FD40D50A03BA589D853E3EAFF8F02F01FBB950B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024974Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:32.108{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50854-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024973Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:34.387{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64E4008AFED6B8495376C19015101567,SHA256=2FD0B285BD5BA0578AADAAAB0645DDDDB2434DAA3A340C5820C646BAAFE15760,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043912Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:35.730{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=43E8E7CC113C75F0023F3D10A4A24142,SHA256=86E489A949409D98EDA6E7853956B43CFF29AE9709CCEAF0C5A97398571DF51F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024975Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:35.387{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5D18F0C1BBA7A5BAD477C1D94210820,SHA256=1B4D1EA0DCA3861DDBBDEEAA5BCB2379514666CF980FFCEF37928F78505853C5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043911Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:35.515{323FE7D8-022F-6136-1600-00000000F001}13082520C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043910Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:35.515{323FE7D8-022F-6136-1600-00000000F001}13082520C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000043909Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:33.365{323FE7D8-022A-6136-0100-00000000F001}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51592-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local445microsoft-ds 354300x800000000000000043908Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:33.364{323FE7D8-022A-6136-0100-00000000F001}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51592-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local445microsoft-ds 23542300x800000000000000043914Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:36.748{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C4A8B92D6C772A9BE87EBA09ECFF6DA,SHA256=D297DEE211B3052A84EFD9A9689B979E9BFDA977CDA84E8D3C60A4FE24E0A9D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024976Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:36.403{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FBCFE53E9E6782AC89C5670D94F8F90,SHA256=992D15D271BF230E1DC2F890C1F74CEB0E6657E20B4BA612E7AC49517459C620,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043913Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:36.183{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=B0FADE96BD0EA8FEC5C9547CE1E1FDA2,SHA256=0DA54076230CA6412588D1450BA36D333C5B580BDFC0EE1C76CE773CFAA6B1DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043915Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:37.783{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AAAA151EC96B5359804C4FA40FE64857,SHA256=3E8853BAE61FDEC8F0AD8894C08049BA1B519C6436169EB2E82515E183A08897,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024977Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:37.403{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=718FEC9B7FE789A6553BEDF0DBCCEFE0,SHA256=07DEBCF7B470061EFFBAD9EC1334A36DDEABB99FCD9F1091DE533A1AECCEC2F2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043917Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:38.798{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CDF216EEEB6117F44AEFF8FEE716B90B,SHA256=F38BA87B76B57A61861C73748E75A9073EC7A69FA7401FA2E258A1642121DB88,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024978Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:38.418{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6EB45683759D984E0C345E179620CBCB,SHA256=7CC29910F35671012EC58BBEE21964C807F006668A0159379A9DB3F33706FC07,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043916Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:35.693{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51593-false10.0.1.12-8000- 23542300x800000000000000043918Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:39.829{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1F0E036CC8A231B049BAF04C2EBC4F9,SHA256=BDAA1AE51F2ECF7FBAD8F1328FA988964D434472C2F0F4CD5ED5493E932A3B6B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024979Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:39.423{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9E95D47C2595883B7121BF4CEBB4E26,SHA256=F117CBFCCCEFE40933F9A69D6A17E3F9BBD00BA5143BEF775F5CAF7273A3D0CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043919Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:40.847{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2CE2B57955C17DCC9E9395B6E44505EA,SHA256=A15CA6FD281F364C96CAE15F7428BB0D8A2F9B72B01740C6EF18CD287965B1D0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024981Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:38.077{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50855-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024980Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:40.501{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=389BED404239665566D2CDE3E2C25996,SHA256=6E33C2D65A8EC3863FACC921A3A7AD5163C8770917AA92BE52FDBAC103A121B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043920Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:41.870{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1279DCCB620F44E9005CF031EB8876A8,SHA256=CC95CEE49185A7E14870489DB0F6226E2880B838A52F6964879C29FDA132AA36,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024982Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:41.517{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3386204EDAB437D779C73B5E0021527,SHA256=21071227AC5F0B37B8D6F6DC5A01D052A007DE2CA94D3C3B25304CE3594CF110,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043922Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:42.880{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9924282B14D4306567131B7FD4EE2C0C,SHA256=E6DEF88E0F211AD6AF887FEDABAFF941550FF9C2BD2D2427396CEA0C8E6D3DBB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024983Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:42.517{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=753A057300F03BF39E3E8E05AF5DB13D,SHA256=636F5E5FD35C005B195D0D8A06C23B66494FB2832C923E5DD5FD59A2E52CB99E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043921Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:40.791{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51594-false10.0.1.12-8000- 23542300x800000000000000043923Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:43.895{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AF45E7370ABA3501FD74D415367F32EB,SHA256=4849EE7DA108AB0111ECEB4F99978FEB152D2BCF145FD9C6F052E19ED66D0A14,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024984Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:43.532{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CEEB3CBAE5510B061EF8F3A9183FC8C9,SHA256=0D42BB69CD4E60A7058950172726C312F6C2B922A5F991BC77AD26F896D02DE3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043924Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:44.925{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F590BE19D630AB1B57A1F50346CC054C,SHA256=8D33778B4E1BB7C07B35E7A94772C979A2713C4A75DB7C29908F60DFBA2D9CA3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024985Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:44.548{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0189704CEDA7F1B86C50D82C2FBA5323,SHA256=B853A9765D4C72BA1747B845A50700E18D090AB5AC7C7AE53103D7C50E5E3A9C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043927Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:45.944{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=72C872516D16D34EAC95C8266DE222EB,SHA256=A4C0D71638874A4761F69905176417429083D2B75D242B2F25C09506B2BB276F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024987Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:43.848{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50856-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024986Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:45.595{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F7CADE99A386C07985817CCC072F36CA,SHA256=9E64C32D6F1E77971C1AF8DA68612B98569EE3597DF3604E5487086EFAC8B38E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043926Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:45.594{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3A0AB0DBFE53026B5582930159BBFA26,SHA256=492DF6D1CED0AF675845DE70593204F0F2B3614709F4D58D52DB61CAACB1D2F1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043925Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:45.594{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C82AB87BEE153B176860E32796E221CA,SHA256=B707E4B33F2A8C501A4704FC2E572F3327B1B9FBDEB667CAC077BA0EC404B8C5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043928Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:46.993{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F62488CAAF86504FCDE74330C304C93,SHA256=46C89B970BE9E99726CB92245F91DA0CA636171404E5A9055FAC0E1DB673DEF4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024988Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:46.595{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F067DA319FF5E8771FE38B54D1863DC,SHA256=2B9136BCFCC1417FF41E218C01CF11DC5C77AE2167DE93C777C525A9191DEE67,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024989Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:47.611{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=424F091D8A7C803F0E4559F51ED9F760,SHA256=CBD743E12F9EC39145DC1624156687D4F60CD61CEEC327F6DF5516CA4A0BF453,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024990Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:48.626{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C13D60749E588BF5B962E477FD2F293B,SHA256=70BEB1CDB6109C8FCDD0D0EC163E4675E7355C5E593141BAE5CC8D8D5A705DDF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043930Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:45.835{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51595-false10.0.1.12-8000- 23542300x800000000000000043929Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:48.008{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9C1E9AFD74DD9A5804BFFD028DD75F62,SHA256=42E39C3C9CE33417C3D8761BAC8B6A51DC1CA7D39CE4B8DD325D0C130EF3BFE9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024991Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:49.642{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5E1FAE1E36184EC832CB5EC41362BC4,SHA256=5E1C7957E4558D69DED8443D9088670FF9B4A26F27E99ADB2B48EFA8EAD1FCED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043931Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:49.009{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4B722FAB08D091C7184173A966A27F91,SHA256=4694F5770344A53E9D98E83AC418958932FBA3EED11BA85593EC9AB8DC19DC1D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024992Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:50.642{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=162B0D66379B4D37CB414C052894565D,SHA256=C255BE4640235213C9D930DABC4A0A13527EF6A259AA63AF058B6BD2564E1D90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043932Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:50.025{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA398086F29DA0624A6973CB6230D994,SHA256=FBC2C1199EAFAF9516AE3D848C8B6B766E5EA54E21F7014ED97F8714ED6F511D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024995Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:51.642{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FDBD2464334E2508DEC794557B6A1B2E,SHA256=E0F8B19B435C57C7507BB8B8370023A1B488D38918F86DC90A4904992CF64556,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043933Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:51.062{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=614FAFFB7DEBB1F8EF4875DF8A4A4C78,SHA256=25453308D1924071CDE148CDA38BABFC6A3D44F4426CC05919957143B5E0B432,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024994Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:51.579{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=C80F39955F683B34C230D095BE8A7247,SHA256=B3C32290AE954774F16E4AEF9787060B3389AFFA81ED986C43C217317C5BF45A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000024993Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:48.910{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50857-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000024996Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:52.657{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3729C82D4B17968C4A8F84F9234C09FE,SHA256=0CE0AF5769CE943054F916BBEF23EE41459A506648B4137342E4D775BF1AF4C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043934Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:52.077{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9CF331F8EE0A15EF19EE6D871270E0E,SHA256=3D66F408F7647DB0F623394C1C8711CE3DE107863372CE86B56DA252833522EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000024997Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:53.673{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26739662DB162A664EA99710CF1AA775,SHA256=C782C9ACC1A3CEB3C2383E0E7CA6BCB3E5091E16FA527F5804A0BD2D2DF7D103,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043936Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:51.619{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51596-false10.0.1.12-8000- 23542300x800000000000000043935Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:53.092{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB120DA8BBD82404DA464BFD30F3D168,SHA256=155FBB098F9309ECF58992013C335DCE4AF27BC999A2AB66F2D093EAC8C05715,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025003Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.736{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=604AD792F9033E39F18F2B50100FAF46,SHA256=CD0FA6616DE9E51DB22A40AA6753F93F7572F6C63B2A16ACEE5386CA47D3E8DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043937Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:54.107{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3E7D382BD49C5AAE2F60BD50EC1D5C86,SHA256=99185B523FE5D0A140A3F898E70029498B908509290444FB6A29BED112DC56EC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025002Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.673{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=52D02EAECF72729AE97352AC370416B7,SHA256=AE81612F928630C7FAAE21AF26AC58170495730C3317CE4B27B330A0502B434E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025001Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.673{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=A37D1B11558979738D6CCDE00D8C4923,SHA256=661DAA12838866305827EEB2C1E979B11CEE108D3219B2F1DF5045CAF7BEB5A4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025000Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.001{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1600-00000000F101}1252C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024999Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.001{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1600-00000000F101}1252C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000024998Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.001{FFF7FB96-041E-6136-0C00-00000000F101}728860C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1600-00000000F101}1252C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000025004Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:55.736{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=318BCBAA88A9205673D7704E1636132A,SHA256=3DBEFB113EB3D45EB680CF0A6DFC629031E195A5FC4EABB44B68108FF16B9920,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043938Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:55.122{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=58E7D3106F38262FC573EC39A7B9CCD2,SHA256=9B59EEC7E192FD0EAA35DE740F62B8F20CE914B9D13D66A09AC0F95258E9C400,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025005Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:56.845{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24BF804FACA48E1BA0418FBBA5249A61,SHA256=F1418D5671B7148F3795156BB3D9D81A748F2980A3387D5D374D4EDC61E383B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043939Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:56.139{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB0B27389F732CD03BFE35F190E932B9,SHA256=7588178AD2A335F83611F3C2C1F259BE518E980A0D9AB194D8CACD34D7AC2249,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025007Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:57.876{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F0434842D683D6407F7ED7F6592367A8,SHA256=DAF6FD4EEE1897F2EFE4378C4F76E0EBEDF4A40D6C24F268B5257F30AA935D72,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043940Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:57.151{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3589D77F9BD931AA490E811F37F6C9ED,SHA256=2D4BCFA233CA573C0316BEFDAB2C872603F780273E3E7B089E1741E2BBAFD149,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025006Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:54.910{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50858-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025008Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:58.941{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=83062D08EBF2B02E2DD479DE04FE3FB4,SHA256=A7A65165F16E46F292EECACA69458F14C6F73E9969411652A8F631CE79F8F79E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043941Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:58.166{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A53E9EBC3EDE74CE54A1F8AC1516357,SHA256=7BB3F54FE5C56A845291CEB9B98A4146C96828652FC53FA4E286ADD102308200,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025009Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:37:59.972{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E786D37265734D3735F081BA93E11E30,SHA256=A6196AAF3BAF1C534B3F58F874A6F73DCD9F2DF902B8E808A37A9EF7A635B14A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043943Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:57.639{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51597-false10.0.1.12-8000- 23542300x800000000000000043942Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:37:59.181{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1BA210C777117D96C6BED57C637AA12,SHA256=F354F074734D9DC5064F13BEA7C91DC47BD57C3C310EDACC3E10E62D8FFE7482,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043944Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:00.212{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8362B597057823AD9E6405C8B7B52F32,SHA256=D049D6EA1A2CC6BF295D663A4828272C3E4AD77F1B68386CE136B7D5AD013CFD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025010Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:01.050{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=482624DA1491D51AC883AB420EBD7D94,SHA256=832A1FB8C9ADBBCAED596BBEBFA5AA22309CA3006580B96E65BD14E77F240527,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043945Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:01.244{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CED41279F708B370611D3DBA9BC17FF7,SHA256=F856678743B1A51FBFA5AB52C8D5193542A130F804517C4FCB92EF82F415EFC3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025012Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:00.897{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50859-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025011Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:02.128{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EBB9B7E3CF305C7BD6DD25B393713D92,SHA256=EF78C23800C36B30E66D425E848F691E9A9948D4F15EEAC9B22850BD6628EDA4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043946Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:02.279{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C95AC66547EFC161BD354F71831B0FC3,SHA256=32DD0AC52185E7BF1902CD5F080137CD3B50A857EE7C26B8B0AEB0553040DE22,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043947Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:03.289{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6A9D7FF41D060C21DBF6F9A6DDC73569,SHA256=D0259E3A5F99A58CC6DE452DEF1C91F3A7C44A769A18E478EB11F3E30893BBE2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025013Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:03.160{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC7403B835E6CDA6653B64573F982903,SHA256=98A3E871FF4612C5842C9786A41D218885877661C6FD1A1A61D3279C4010D1AE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043957Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:02.699{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51598-false10.0.1.12-8000- 10341000x800000000000000043956Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19BC-6136-C308-00000000F001}864C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043955Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043954Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043953Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043952Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043951Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-19BC-6136-C308-00000000F001}864C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043950Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19BC-6136-C308-00000000F001}864C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043949Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.420{323FE7D8-19BC-6136-C308-00000000F001}864C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043948Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:04.304{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D861992EBA7A6E7E1C16E3D48837A8B3,SHA256=A10A6260FE900A9A809B0B6D4DF39FC9ECEE98BA22AE4E37BA646B3686702CD6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025014Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:04.160{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=201AD2C412D6DE3E5B49662B469317C3,SHA256=ECCF4B7213100BBA9730FC05C2362DE753C4B5662A2B1947E11D982F53F88DA0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025043Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.785{FFF7FB96-19BD-6136-3D06-00000000F101}40323384C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025042Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19BD-6136-3D06-00000000F101}4032C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025041Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025040Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025039Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025038Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025037Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025036Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025035Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025034Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025033Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025032Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19BD-6136-3D06-00000000F101}4032C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025031Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.644{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19BD-6136-3D06-00000000F101}4032C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025030Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.645{FFF7FB96-19BD-6136-3D06-00000000F101}4032C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025029Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.628{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025028Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.160{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA4B7B62C490A86FE385BE014D006CCA,SHA256=FD9FEC55F94C5DBECD3629EB34C3DC914CE5CF360A53CBCC389C7F7C09F38535,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043977Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.936{323FE7D8-19BD-6136-C508-00000000F001}17484368C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043976Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19BD-6136-C508-00000000F001}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043975Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043974Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043973Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043972Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043971Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-19BD-6136-C508-00000000F001}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043970Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19BD-6136-C508-00000000F001}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043969Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.774{323FE7D8-19BD-6136-C508-00000000F001}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043968Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.505{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=67E7779DD3A4EE4D858DE931A4B08A88,SHA256=A4F797011C16650912896A679B87E41ED7460D11195AB33D8F7DBA6F79831017,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043967Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.505{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3A0AB0DBFE53026B5582930159BBFA26,SHA256=492DF6D1CED0AF675845DE70593204F0F2B3614709F4D58D52DB61CAACB1D2F1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043966Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.319{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F943FE45E9F706FC6743F0215B2B2167,SHA256=8EC01DB3B1ECDCC7B5D7D785F41191A06E932BAA49967AE04E494B61A47F5905,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043965Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19BD-6136-C408-00000000F001}6396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043964Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043963Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043962Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043961Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043960Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-19BD-6136-C408-00000000F001}6396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043959Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.103{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19BD-6136-C408-00000000F001}6396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043958Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.104{323FE7D8-19BD-6136-C408-00000000F001}6396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025027Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19BD-6136-3C06-00000000F101}580C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025026Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025025Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025024Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025023Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025022Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025021Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025020Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025019Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025018Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025017Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19BD-6136-3C06-00000000F101}580C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025016Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.128{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19BD-6136-3C06-00000000F101}580C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025015Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.129{FFF7FB96-19BD-6136-3C06-00000000F101}580C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043979Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:06.573{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=67E7779DD3A4EE4D858DE931A4B08A88,SHA256=A4F797011C16650912896A679B87E41ED7460D11195AB33D8F7DBA6F79831017,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000043978Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:06.320{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E295FB3BCCEE015C04D4874DB9688FFF,SHA256=B0B89CB665FE98480CDBCF74C4EDEAB134B27D598F07FF3ABE7D8A763C2FFC85,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025059Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19BE-6136-3E06-00000000F101}3752C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025058Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025057Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025056Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025055Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025054Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025053Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025052Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025051Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025050Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025049Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-19BE-6136-3E06-00000000F101}3752C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025048Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19BE-6136-3E06-00000000F101}3752C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025047Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.316{FFF7FB96-19BE-6136-3E06-00000000F101}3752C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025046Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.175{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D2A5F71FB7207DB4B253E97F0D18790,SHA256=EA964628DB513CBDC4387F80532D517CF5879D9BDECCED655C310122231C19A9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025045Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.144{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D381B447C46F67668152F2476087F90C,SHA256=EDC0B8AD2622BED21EEABB22CABB2CC9A67B550E02ECFA3B3E414FDA43B1F089,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025044Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.144{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8857280EEAA64C6F5DD6B2B8C8A844D5,SHA256=91AAFE72505138D7BC102DB2036FCA06F8AE6B7A3A1C105C40B8042E38D8ED34,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000043985Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:07.373{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-022E-6136-1500-00000000F001}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043984Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:07.373{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-022E-6136-1500-00000000F001}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043983Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:07.373{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-022E-6136-1500-00000000F001}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000043982Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:07.335{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AAAD85BB7EB36FE7AFEC022A2CED245,SHA256=1170DA20C7C5823882F457973E6CC1C3C19C014EF99DAC66C973FFD7186642C3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025077Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:06.053{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50861-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000025076Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:05.459{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50860-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 10341000x800000000000000025075Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.519{FFF7FB96-19BF-6136-3F06-00000000F101}36844092C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000025074Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.425{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D381B447C46F67668152F2476087F90C,SHA256=EDC0B8AD2622BED21EEABB22CABB2CC9A67B550E02ECFA3B3E414FDA43B1F089,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025073Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19BF-6136-3F06-00000000F101}3684C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025072Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025071Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025070Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025069Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025068Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025067Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025066Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025065Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025064Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025063Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19BF-6136-3F06-00000000F101}3684C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025062Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.378{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19BF-6136-3F06-00000000F101}3684C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025061Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.379{FFF7FB96-19BF-6136-3F06-00000000F101}3684C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025060Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:07.191{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A5AE0E601C75739719560655DA7FD76E,SHA256=3E80FB2B761D4528480214E4B9413D0E700B973437DFEC9526FE451AFECAE57C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000043981Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.147{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51599-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000043980Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:05.146{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51599-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 10341000x800000000000000044004Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.989{323FE7D8-19C0-6136-C708-00000000F001}48363828C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044003Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.755{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19C0-6136-C708-00000000F001}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044002Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.753{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044001Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.753{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044000Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.752{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043999Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.752{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043998Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.752{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-19C0-6136-C708-00000000F001}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043997Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.752{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19C0-6136-C708-00000000F001}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043996Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.751{323FE7D8-19C0-6136-C708-00000000F001}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000043995Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.357{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C424CD7C2B7874890953D6C7FFFA578D,SHA256=DB47315740988097C97E1D758B9CF7F23359D0235C775EF0E9C9E787567E4C12,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025106Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.863{FFF7FB96-19C0-6136-4106-00000000F101}992996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025105Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19C0-6136-4106-00000000F101}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025104Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025103Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025102Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025101Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025100Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025099Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025098Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025097Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025096Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025095Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-19C0-6136-4106-00000000F101}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025094Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.722{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19C0-6136-4106-00000000F101}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025093Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.723{FFF7FB96-19C0-6136-4106-00000000F101}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025092Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.347{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=391325262F68D5B753A28B1F580EF045,SHA256=3BEA048FC5AA16952C3F339C72B0790BC1F9C3B64E2FAD3FAB247E7FFBDBF061,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025091Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.206{FFF7FB96-19C0-6136-4006-00000000F101}13721296C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043994Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.257{323FE7D8-19C0-6136-C608-00000000F001}16762856C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043993Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043992Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043991Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19C0-6136-C608-00000000F001}1676C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043990Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043989Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000043988Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-19C0-6136-C608-00000000F001}1676C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000043987Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.072{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19C0-6136-C608-00000000F001}1676C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000043986Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:08.073{323FE7D8-19C0-6136-C608-00000000F001}1676C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025090Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19C0-6136-4006-00000000F101}1372C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025089Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025088Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025087Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025086Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025085Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025084Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025083Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025082Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025081Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025080Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-19C0-6136-4006-00000000F101}1372C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025079Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.050{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19C0-6136-4006-00000000F101}1372C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025078Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:08.051{FFF7FB96-19C0-6136-4006-00000000F101}1372C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044015Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.620{323FE7D8-19C1-6136-C808-00000000F001}41405408C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044014Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19C1-6136-C808-00000000F001}4140C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044013Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044012Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044011Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044010Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044009Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-19C1-6136-C808-00000000F001}4140C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044008Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.420{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19C1-6136-C808-00000000F001}4140C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044007Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.421{323FE7D8-19C1-6136-C808-00000000F001}4140C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044006Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.373{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98BA82DAFDAB20F126884C6145DF7588,SHA256=D69AFAD3E8A416EED59DE4D001EBD1028995D29783AB1AFE38B385655B3B8B77,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025121Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19C1-6136-4206-00000000F101}436C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025120Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025119Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025118Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025117Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025116Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025115Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025114Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025113Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025112Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025111Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19C1-6136-4206-00000000F101}436C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025110Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.394{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19C1-6136-4206-00000000F101}436C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025109Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.395{FFF7FB96-19C1-6136-4206-00000000F101}436C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025108Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.285{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0C9477B131719B628607444D93B9297,SHA256=FE9DDE7F7C0AEF22192ACA26196D85296962B7A7F10B517D30406213439616A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025107Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:09.285{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B143447BF29B8E080CB030862D7A381A,SHA256=B3895F6A81A1C7D0E7004F0928761086296CCE733B642527AD88743B8585EB47,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044005Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:09.073{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=57CA774C1A494098F21EAF372FC74EB0,SHA256=D25B3EC38F754C6FE8872F3F77DB2F074D0DA3217AC57F4F3DBB15AE0F7B5A66,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044026Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.421{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=92725F67BAEFBAAFA2372E2556BCCC81,SHA256=2C6DFD32073C94EAF0E246E684510C25783FFE9BABA622EAAD893A357DEA5E71,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044025Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.390{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D33E42C11A3A6A4B0CDFC1E368FACC01,SHA256=292C4519B15A6C1CCDAD4E01E59AEAB2D517C65F8D8112F42920532D714C64EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025124Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:10.913{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-089MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025123Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:10.411{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E5D26DB67F92C4D0A52883152ED6BE1D,SHA256=C63BBEB905B7C7B14A692D94FEA4A2463986C1E2DE200FE89339AF451509C102,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025122Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:10.285{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=184F3835EDA74C92AAF26915E296957E,SHA256=43D8D325348A5C614EBDDF29C615F73348EDE9812D7EB1DFE684815370F9796F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044024Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19C2-6136-C908-00000000F001}3720C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044023Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044022Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044021Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-19C2-6136-C908-00000000F001}3720C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044020Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044019Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044018Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.088{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19C2-6136-C908-00000000F001}3720C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044017Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:10.089{323FE7D8-19C2-6136-C908-00000000F001}3720C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000044016Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:07.797{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51600-false10.0.1.12-8000- 23542300x800000000000000044027Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:11.404{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F7F7D8433F9ED2C398CDD315EB8BC2B3,SHA256=C7332F3AA10545B61AA906F92418880F31C43DC8EBA654AD25A9FE9D256AA1AB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025126Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:11.926{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-090MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025125Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:11.300{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FCEDF7E6F84AE0839C434E979D2EB96,SHA256=D980B85DD3103A966C4643F5B4873A6390B73E2AC45392C61D468728FC537B2B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044028Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:12.419{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD04B1B395F47FB3979A748C73FF63C7,SHA256=5C62767A339C490ED097CC88AEE39156D9411B5BA93936F033676A5E36220CE8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025127Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:12.330{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2BF0C4387B544B0416BB55D00E515E69,SHA256=34C2F21A8B93E7A4587914A0E187DC7D4E51F8258B6E0ABE4102F070BB0FB22E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044029Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:13.452{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E8B783140CBEE54C8B9068C9E4EF9F7,SHA256=676F7D958C3D7AB7EA732713D16476BDF1123D26134B3F88818630BA83E1E148,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025129Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:12.098{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50862-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025128Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:13.348{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E0196512C33FB098FDFDE670E738ADC,SHA256=AD322782CD429444D60BE157848BC101850B96C7DE668154D6FFDA63FB180837,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025130Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:14.364{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=323136A60366607364967A68D288AC81,SHA256=34AF45B967A8BEFB27B971494614CEBDAB085FF413274F2C7E6825D4F3202A52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044030Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:14.471{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0F60D8BB25FCA8335B82C9E4D95289F5,SHA256=4CD342EB1AB3F08E5A22B857DC3F1566550CF5ED1899D576EF6AC20824D05947,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044032Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:15.486{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A6A9E0ED9BE0B1228AA0C30BF63EF018,SHA256=68DC7AAD778B5CB9921B7213E0840506352B13C49A1C7169E41B2E4292D19F43,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025131Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:15.379{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F00AE41752CFC52EE0F380233DD85F4,SHA256=1101EA66D129CC8AFA1FE54C5F16ED4A8C8FE9D4C6DD685C11D14D82362A429E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044031Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:13.644{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51601-false10.0.1.12-8000- 23542300x800000000000000025132Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:16.395{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5CCEE867CA036DA8492A0CC5D35BD70,SHA256=12AE20B91314596D3BAF81D287C1C35C4DB9B58980C985F52E43BDC033E730FF,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000044036Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:38:16.532{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\9752B235-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_9752B235-0000-0000-0000-100000000000.XML 13241300x800000000000000044035Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:38:16.516{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\CED8D70C-FDB7-4280-B713-3A56B1B8A289\Config SourceDWORD (0x00000001) 13241300x800000000000000044034Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:38:16.516{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\CED8D70C-FDB7-4280-B713-3A56B1B8A289\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_CED8D70C-FDB7-4280-B713-3A56B1B8A289.XML 23542300x800000000000000044033Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.501{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=220E9614D947483527CCD97B338C4DBE,SHA256=85341C5F13B56CF2FCD9ABC53EA13CCAF385A8ACCF0AD84DD5D85984E9F70CAC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025133Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:17.426{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB5D04A7F43E4A0A1902E1FB9F09727F,SHA256=DA3AAEBA084614B5DA8C0D98B8D6B0A292E047B9168E17D27A5792FEABBBAC91,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044041Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:17.569{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D9922126A895780C479C762AA4DC876E,SHA256=D4FE2488B8144B37F5EAE9A9D7279CC7AC8BE8BC89A33526BDF66A4A200FA966,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044040Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:17.569{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=55CD4ABB61DC73ABFB0DB572F97049AE,SHA256=C7417E9B24D769F090CACB9D3D66EE8A2E0706DD363551A79C2304F90F3C3F13,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044039Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.112{323FE7D8-022E-6136-0D00-00000000F001}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51602-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local135epmap 354300x800000000000000044038Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.112{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51602-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local135epmap 23542300x800000000000000044037Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:17.531{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6DF47953159FF8B48C17553B00D898A3,SHA256=7AA494BF3C81A7CF09F82B602CD406E04D9B39A7E72AE05F55C1DB372061BF90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025134Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:18.442{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EF82E11703869E1CA328409E69D1D5B,SHA256=DC575B7B4D00DEAE9C842179A98D5B2C6D118E35F0DA5EC878BA1DA87039ED3B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044046Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:18.553{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EBDB121F38F650588A674A42305C4C00,SHA256=E8DA44EF52E69C56B123199725EC9745DC7A7A89E6C2410ABAC7EC5B95B186B3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044045Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.135{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51604-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044044Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.135{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51604-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044043Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.128{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51603-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044042Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:16.128{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51603-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000025136Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:17.913{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50863-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025135Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:19.446{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=342856766A485A37DA8D0ABB0F20CFEF,SHA256=5DCA141E5638ACED41ED4F06DCB044C1211BD5363E574591A9C63CC4E07C5539,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044047Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:19.568{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC1EAB06B07A9BBAA294249067431E63,SHA256=D8462615B4678FB19435A94F8A635351F9895C928C4347A1DC92D97DCDC3D88F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044049Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:20.582{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=578F25CD094CF721637C375872E9E0FF,SHA256=90B613BBCDA8BEEB84B8D92035F2A5C7D2CDC53A99CB408CB2381515ABF8563C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025137Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:20.446{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9803DEACDF5CA8689BBCDB8050605E4,SHA256=12B4B228CDD8B341A5EF8213D29CD0E30E0D99546E5AE22B2012149BCC1D57B3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044048Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:18.744{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51605-false10.0.1.12-8000- 23542300x800000000000000025138Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:21.461{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=83B492C5661B72CAC0F58CBC8057DDBB,SHA256=E83214A5FFAB81F347C7BBF0E5430B6FF0FBEE31637CCEEAC29DD1ECC9DB8798,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044050Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:21.598{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=561F8EC2D2A63FEB68A0F7679EFCC092,SHA256=A21AE08B329AE1C6780B4B1070642F091F0F77FCF113B960840DB13E0C0091F0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025139Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:22.461{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3BE8055244483D95F049D1C2F1246A23,SHA256=8F8CDBF9B298BC6521F11D4D318118DFB4934A2AAEAF7BD51F1178AFC8FD5330,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044052Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:22.606{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E848710A23CDABD10DB5EAAA59331252,SHA256=46E64B672FDF6ECA48570ACD193FF5E5013AA1C23B599DC0C9B3330D12AF468D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044051Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:22.547{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-097MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044054Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:23.626{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B94F8EB9374B4ECB9518432A8F043D85,SHA256=7679C31D3319DF7B61499341D70CF9AB069DFFDEEA21157A0B82F6F0B37A4B39,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025140Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:23.461{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=613FF72799C0E8C1724DF8C9C2491131,SHA256=F540104DB6CAAFE046B10254BCC2C96B53438326C961E0B8A6F86E3FC04E2052,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044053Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:23.566{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-098MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044055Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:24.628{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=55CDA1210466215F339819B1DF22DF0D,SHA256=3E685A497AD099A0B60086EC90BD2477347276EC39A753832AF4AE578C207D48,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025142Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:22.980{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50864-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025141Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:24.477{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8BBF5D7C4FA5CBC4729335EF6FCDFEDD,SHA256=CB6815C6040A1DA5D82795FD481854F7F4B535D687D1E548C1DB11B36B9A3CEB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044056Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:25.680{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1F3D096DE72CD10065159DD4318B403,SHA256=5A9D6F41B72331A9B74E9958D52408D017EA7FD26BC675E8402AF37AFB1B7384,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025143Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:25.493{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=127AED1E7D202EA225F68635BC1AFBFC,SHA256=69767DE28FB5424F5F58B4ADC4F8627E7CE61B8FAD5A8566108172E3867D4634,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025144Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:26.524{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=61F5BC0E88AB7D30E6C0AA801B031A58,SHA256=C4E83C83F5A0ECC0DD0F6DB645A44FBB592638B7556E709877E7D13CDE682B75,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044058Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:26.695{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A9A27BC1A5F58DE3F4FECD3809D0F2C,SHA256=E91CB1C628163701FBFEAC7E3909BAE4B85D94FC0686D8885A0CC3BF019E6271,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044057Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:23.841{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51606-false10.0.1.12-8000- 23542300x800000000000000025145Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:27.540{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BE5E57E1F011A0F3FC5D53435C01411,SHA256=AD66B4B17657DEDB65FC96358D56B29C8A4A0060B540BDEDB1D5643E5A0F8E7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044059Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:27.726{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0E5C80AF54F83A642CDF82218F339DD,SHA256=468D17BAD69F83DCE2064E634D18227E72EB399DFC7ADA387CAA6C2D76D148DC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044060Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:28.744{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=01B77F074EC7918301F6D580189433EE,SHA256=1D67F7F9E8D80B4270A7F76C46BE12ED384ABAEB195CE11321B37759FC77E68D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025146Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:28.540{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8FA81516DE23C54028BCA10F8E8835B,SHA256=EC7AE944B0A1AACED5BB113026FE6763F8866D42ECE68D3B8071EC6662D815D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044061Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:29.746{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=864B709FFC1111DD2D96FE45177B9E25,SHA256=6A57869D957614869E0A8D4EB93F72D461D3B83790B3ACE53A856F2C8903C9E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025147Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:29.586{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F469FE73B953AEF3AAA097844DDEDE12,SHA256=2FD1F24400237F5BE2CC0E0BDC7346922490950AEF34FC5CF54DAF85DB74839E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044064Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:30.776{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EB738BE57B2090B9FBE1B117B74522C,SHA256=8E036C4FACA27109ECCEB75A6617B702BCA92FEAB21996DBD0802478D6BE0829,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025149Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:30.602{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6118D741FABB4CA8649DF19D23F729C7,SHA256=4C6BA22422772799569A3FBE15E182550A0A3830B28DED3039B38AAE03331EC2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044063Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:28.856{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51607-false10.0.1.12-8000- 23542300x800000000000000044062Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:30.144{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025148Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:28.011{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50865-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025150Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:31.602{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=66B0F823FF0BCFFD71ABC9FE6017CD8C,SHA256=F27354DF87569F962183710930402027D450967B5D2338278F73184BEE671BE8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044066Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:31.792{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9CED2B728405D8D960B44E4FAD39300B,SHA256=75527539E604C4941E9C4F242D2EAA79F9AA9245F5D30491F1ADBADD9807F956,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044065Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:29.718{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51608-false10.0.1.12-8089- 23542300x800000000000000044067Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:32.807{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05201E3E9DB4968ECBC9F809B4C15FD4,SHA256=0D41A46B94011FECB180EF06A2886DF40C8C2DBE58F03EE4578AF8DACA388D69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025151Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:32.633{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1AAE5459099F39DFA61561A6FBE97406,SHA256=362E047D5EAD99B18BC15C133DB1B387372FA0763D0CCE07A1EFADB37E51A6B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044068Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:33.822{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FCC8DC530057FF41059B99692E3D5705,SHA256=3D1D4A033C517CFCE81970EF286E854C6EA6B0E3BB4D1ABEB0039AA74748EAF5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025152Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:33.649{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8697518F4198385BE73CAA3A114F2FBD,SHA256=7FCBAFEB6D32512FC3117284F08593EBB5D0F9B62A089590BED3E85F3F07CA90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044069Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:34.839{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD5636D385CFBB360C26DC9EE72FA5B1,SHA256=C7B4A82D61D6E0B119CAD83AE0937634CB04248048D4816F9D1DB7CD9F1E0F72,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025153Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:34.665{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=231289A4EFC8B6CF342E5E84C13654D0,SHA256=A9B275B1894AFEAEC57AA97F14BF5B2D380DE6E03E9EC22189134A8B5F1BA710,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044070Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:35.858{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08C50E735903F42B5DE1CCD6540B7D94,SHA256=A171C07238DB8769E97CF40563FB5DAF23370C28E2B3C326C7C841B2B2A10D82,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025155Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:35.696{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1397372EC61A4B7EA7B1B86CD97AE08D,SHA256=74469AE5E28101B866FF525428FD011554E06B4D45E783769621A2AFEBBDB670,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025154Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:33.058{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50866-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044072Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:36.873{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F13DA49110A2C756398DD85D751A7BF,SHA256=BFD38F2C3D05E8B0C3E99EB31347ED78201AC85F1938D413C8993A06917E98ED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025156Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:36.696{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C8E0254E47F8EB4C1587A77E039D54D,SHA256=F5C98483C72092116098B46C1CB340090A9273750B803BAB0480885D1958AF5C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044071Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:36.189{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=9E31A95769286B929C70B1C3E95C18C4,SHA256=C0A93949A36C98794B683AB71525E5D1B6FF3054AE483BF7D0255349D71BE505,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044074Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:37.888{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B56980966A7C52B41F31D40566F66DE3,SHA256=09314021A582BA5B6DDB868C7BF14F955B2A3E3A6A9321E3C883BAD1255E193E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025157Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:37.711{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=71339CEE5F4CF5DF2F6DDCDC6EF831E5,SHA256=67BD7233240ED6672CE530B93BCA3FD200CF23DFE2AB73DD2123EE6BF9923D19,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044073Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:34.834{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51609-false10.0.1.12-8000- 23542300x800000000000000044075Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:38.903{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D848086D2A6F1DD455C92EAFA80B7DB,SHA256=7F6C3879DEFFA37A9AFC0A91036AC0E163CF9193F170D4EE8D2C7AA9D65C7102,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025158Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:38.726{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C2126968C6BD35014200FB7DA8C25836,SHA256=B748E682BC752304B9CC6CE5C27D51DCE63F2825FEA1538C949A45C088A2FFA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044076Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:39.918{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1BDF07D94A7FA884084421DE6154FB16,SHA256=8C1FE8A822E8DB4AAAD4721D0274C93B88A7E428C76DA00CEC79F49B8AD1C788,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025159Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:39.742{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C4DDB75D3731F5A5160F18AAF3D85AD,SHA256=6EB3DB10AA53D5BB73F4C271F0EE670C3C95358E0E940A78690F83E161022766,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044077Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:40.935{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8105EB632EB97D623E6759ED2A08FD8F,SHA256=E35D2D9E164E2A08392EE277DAF76ED9382AA194E6B61541281C6FFF4634EFC9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025161Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:40.757{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C116832FA43B28BA1C4BD8A21341558,SHA256=87B29EB1B99D07D54C9BA60FF478438ECBE86CBE41D97639DFA4CAA8EECDE7D0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025160Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:38.948{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50867-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044078Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:41.954{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5514BBE25A50C639B8B03058564E6BDE,SHA256=6147563EFE43F52D0644AB003F05EA9A2422FFAEFCFA9B8B0D58C213CB11BC31,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025162Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:41.773{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E39F3E85037013C62BD1B70D80913C8,SHA256=CAC30A0AC5D7436355CF306715BE2B9B05EC05D659D8737107B66898E69BCB81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044080Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:42.969{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C8ED8DF49F342E825D22F6EC41B84D69,SHA256=14948FDE0CA2F5F826C93E1BF146F0EDC80289B0C33CF65CDEDD2A2548787F75,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025163Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:42.788{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D581506E12FC6DDCDFC853891571CA80,SHA256=FD16BBD026EF63FFC00F751E17336FBDD6D8DD4882C0B8A0727594C2DE0529F5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044079Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:40.764{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51610-false10.0.1.12-8000- 23542300x800000000000000025164Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:43.788{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E8F0EA74EB1F29A19D56C61E068B28AF,SHA256=55EACA2DD7E7D7AB8A85AB5A142C6A3A65F6F9E93C4A824D0DD06A3A6004540D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025165Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:44.835{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8EDFB8CC9737B70A6D8586C62F6EB756,SHA256=E31A039AA4F84F5576CCACFF5533D3BA5CC5E6DB22141F38342C6525F670B7EE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044081Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:44.000{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF81515D1C8D36A91C81246DB76219E7,SHA256=18484EC6801DB2F77F05206DF8A53B3FDCD9FE84871FF816463B6D3A1735956C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025166Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:45.867{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9F47C1E059B1DB3CFB7AB3EF4754796F,SHA256=B5CE81128429D884E30EECA1176C2DD672C12806CEAAB5E21EA475861BBFCCA2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044082Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:45.015{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=746E285FB1A980FB2D9EE0F4CC0A2D36,SHA256=CD2CCC6AFCEDCFD5A3EC75010AC92F9D8FE017B6515AF71524C0128DBC7324E4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025168Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:46.882{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F8EA9B2F859C94E461051A1617F5885,SHA256=582F159709D313558A37008EBA0C2E1182B26AF40983C0A0C995891DF6524CA7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044083Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:46.032{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2D7D6ACE929903FD22D4878BCE36D037,SHA256=46B89575B08BE2B3A51834F9B63CB83094FEA46C425DE34ECEB167C3EA2F56B6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025167Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:44.979{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50868-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025169Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:47.913{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A8D90B4770A85B0B4EB4EE215A99DC8,SHA256=EB0C8D585C94386462E8C90914B6A4A3999605D3BF326ABF504A7E1D8F7A7642,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044084Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:47.066{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B3BA041D26A77C91DD0316B646C8317,SHA256=A77B3C8704D84B5DCE699A1DCD71E4FE4451E58AFB70AC81FBD4E845AFA25173,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025170Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:48.929{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5175CF69FF73F61765A1335AD26E3857,SHA256=EF8F3FB906AAA8B8F7D9AEFA6C081A682D757BA300E03524386618898EA6E095,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044085Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:48.081{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=567663D60E5E8169ECD0EBE468BB8A96,SHA256=844CBBE5D291DB89FD77D4E44FD79FFF6C13AA42E9C298804706416C09F893E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025171Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:49.945{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6125C7B84107159628E929EAFB25498A,SHA256=BC60858684D4B0CD156AAF7538F91577D6AC54BB4E056F8B1B5E0C1546C1E7EC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044087Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:46.707{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51611-false10.0.1.12-8000- 23542300x800000000000000044086Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:49.099{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F2F004A077E32A1776B834BEFA7E7CD,SHA256=13760D34E5C84480D40E6615E16BDB07454604410B7F5A8E6AC21CD370C3B602,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025172Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:50.960{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D857755BB5B6A60D771E98C739E3E61E,SHA256=2BC0C09FFA3833907FDAE224AEC3A1E2B9C6B18E273DEE99BBA89404D82C2129,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044088Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:50.100{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64A1FE01E12B071F9E08FBCC7542044A,SHA256=03B602D74C9CBFBDBFEC466B8EF3E2A513EA7A4E8201C113BB386B4BF47A23C7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025175Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:51.960{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=097DABFBA3691C0A3422FF734A02E75A,SHA256=50775B5370F1AC5D9236765AF7EAB52E5A73160190E2E596B5BAF80C64F020D0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044089Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:51.115{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=22C90D30567212420CF116D195E2D5E6,SHA256=B66B7AB844AFC5BDC035E2EF90A826A1D3D079771494C4DEE79FC5C01307ED81,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025174Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:49.979{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50869-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025173Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:51.585{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=1004F04FD8AD340D904B5D801DAAF5B3,SHA256=69E4906CBE9039A7332B4E01C7425DD1D02891B16878518452CB29E5956A60E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025176Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:52.960{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=711CF3BEC7DC2C55A988A1775251FF93,SHA256=B418CC669E4B922474C28BA5645422F20A9AB174B6CBD44D561AF5585EC4D027,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044090Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:52.132{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5AFD2F3F255ECFC7EFDDC9DD043B89A9,SHA256=0223E3AB338382B587A8A1BE052564B5A175FBA700B9F072EB230CCC206D28A8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025177Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:53.960{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03D601610C6BD6C2BD147E5EE9E2ABCB,SHA256=740E1C18C334F7897C3F93CACD29DF966038923B17A04FAB3273AEC3E9DF168A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044091Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:53.167{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D364442036CFE769070099C10FE6BC8,SHA256=75E4A70DF97C84FA6A7427028CC834DCFE3C118C0BEB10E0A26E54A29F966847,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025178Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:54.976{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=357BEDD03ED7947DB842A0DD4B1E6210,SHA256=9152F4DC9BDB278D4759DDFB4B4BCDCE82DEBA379831EB2A28D6F7B9CF94682D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044093Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:54.197{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C2F9D44A304D224CC657CE456012149,SHA256=6FBBD813D15673BC9016E767E2CAC922169BFA5A5B2F13102EE1F3FAA693F1BD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044092Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:51.808{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51612-false10.0.1.12-8000- 23542300x800000000000000044094Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:55.199{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5F094AC9D2B1AD88D4D59D0F1BD4A83,SHA256=B30614BB86C741C7EB8D102C117B8D9506AE9590836B7E255A636E30F45766D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025179Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:56.007{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E0E13693CEA2981F8B9B7902BE970F03,SHA256=329CEA9D5A6A5F137FA037904AC4B80D7D4E582251D0D831F6B4C69FE36BDE80,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044095Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:56.214{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DCE34057F19759214DD8843CCFB20D23,SHA256=5B8AC391A482384356713874CEB4D4591B9B6F27BE252AD8B6A8A2F73436A9FE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025181Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:55.948{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50870-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025180Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:57.038{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=30CBD8BCBEB15998E9FB17CA0282CCAF,SHA256=EFE2CD20A900DC95FA247372AFBD12D6FA309F00273541F25C9ECBDCBDAB180D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044096Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:57.215{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BDBE967CEC2E141BC7EA14B3FB50DEB4,SHA256=10EEAA62F9666D6825F9FA3B0D42D0BD5C45C10690505E3AAEFA74A8A18424D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044097Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:58.232{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5B6C98C320170A8A4211E4AB0394C00,SHA256=9C957E9468D446B3A7E757137AEA23E0CF3CB9E23FE656A904E1F2685CAA3811,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025182Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:58.039{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FC3E008EA1A84F73C3E8D8BF34A70D9,SHA256=87C5B2F35195D6BB64D57928F0CE52DEB9050F9F349B12A1D393C7C74A57705B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044098Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:59.266{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5372AAD08E690278E45384BE358E32DC,SHA256=81DD26525A981E8A7918B1FFB8A04323584D35ACED1A0D446846029CCDDE23A8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025183Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:38:59.040{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=941FB1F4AB649507B10DEF5E739C473F,SHA256=9C2E99348B3826AFD08CAA45972C4BDB51430BBB4084F97A821E9645AF708F81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025184Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:00.055{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=86B88C5403F74FBC2E9C44EAA2756A47,SHA256=CDF4C227FB1901D0F4E2E65F38C9ECE629B3CBA1E66C6E44FC31DFD904057FC6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044100Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:00.281{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CCCE31A98AA529FAE7A00649575AC15A,SHA256=0CD587DE3FFEBCD380118FB4BDCC53034A4E08069CD08EADF71889D3A046C69A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044099Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:38:57.808{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51613-false10.0.1.12-8000- 23542300x800000000000000025185Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:01.055{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A14E7ECB79D139294E90E35E10A1138,SHA256=8AE601EB4DF441FBC700135EC8CDE612891C6A7E917CCE049C281A63C488F07E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044101Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:01.296{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=69E8F0E5FFB7C77AFBD5D8C69E6D0DFE,SHA256=EBF65B6A9D940776022E2B0DD601AAF510CDF30A1B06162664BCBE44D8E80389,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044102Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:02.311{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11BDFEAC71A45821B04880BAA9B026D6,SHA256=BD5A35B1BF5BB2A983F337DCD3332F1AF506AA3BEA2B26A94934D9FD9B698173,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025186Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:02.055{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F407489986D66886562F9A9842FAAA36,SHA256=5E83D435E51D8F3E68CF03B9BCCAC9D02FEDF4D325D3FD6AE9BF1E80C7DF7B71,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044105Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:03.947{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=1182936DAC3C905632D409545A6CE5AF,SHA256=B10E4A104824FC69A4EA61D2027809D6AF65731D32E2733470718A823329C1F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044104Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:03.947{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=4ABAA3306D4472EF769A126A2A8A97B6,SHA256=3A16BC7B0EC9B9AF12BC54C1AAF6C5C4436E797F437BD50ECF9264B0F1233FA8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044103Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:03.329{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=133A766DB0F82D27C40D93236945269B,SHA256=18C6FD09F11C69F1675752D9787E02B121C91F2387104E7746A612BEF0992D99,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025187Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:03.055{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A9B5146B05C0C23DA2EDDF0F6D7BEB77,SHA256=2AB2363C668A5D54870FCCBBBF8F64685B4DB23E81D32E2BE8DF0F922A1C0FF2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044114Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.431{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19F8-6136-CA08-00000000F001}5532C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044113Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044112Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044111Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044110Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044109Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.428{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-19F8-6136-CA08-00000000F001}5532C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044108Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.427{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19F8-6136-CA08-00000000F001}5532C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044107Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.426{323FE7D8-19F8-6136-CA08-00000000F001}5532C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044106Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:04.363{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=55EC9EC895EA13BEBD37E8A1440D0D74,SHA256=1A3C3D59E2E57184CD4835BD8AC4CA11DBAD0DE2E31E50DC8E7C12667DCCFA09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025189Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:04.071{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AA8BA1A5A176E68B4EC42123567F952,SHA256=853131287F71D39A7455AD88EE300BA81AAA1DF4343BC20E82D0BFC0519F35F5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025188Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:01.886{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50871-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000044134Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19F9-6136-CC08-00000000F001}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044133Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044132Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044131Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044130Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044129Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-19F9-6136-CC08-00000000F001}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044128Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.678{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19F9-6136-CC08-00000000F001}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044127Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.680{323FE7D8-19F9-6136-CC08-00000000F001}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044126Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.463{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=336FC13A5539EE5F872243FF73ED2AC5,SHA256=DD8624772D672437A4049FF4C4543DD935DFE718D08189BCF4CC9EBE97738721,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044125Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.463{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D9922126A895780C479C762AA4DC876E,SHA256=D4FE2488B8144B37F5EAE9A9D7279CC7AC8BE8BC89A33526BDF66A4A200FA966,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044124Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.378{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C86527B6A119A43BDAF253935AB86536,SHA256=3F617BA48A45DBA437EBB94C72DA1AB38AC424AEA0B14A562875379AAD2D6419,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025217Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19F9-6136-4406-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025216Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025215Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025214Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025213Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025212Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025211Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025210Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025209Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025208Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025207Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-19F9-6136-4406-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025206Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.805{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19F9-6136-4406-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025205Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.806{FFF7FB96-19F9-6136-4406-00000000F101}676C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025204Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.649{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025203Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19F9-6136-4306-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025202Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025201Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025200Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025199Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025198Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025197Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025196Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025195Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025194Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025193Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19F9-6136-4306-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025192Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.133{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19F9-6136-4306-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025191Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.134{FFF7FB96-19F9-6136-4306-00000000F101}3252C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025190Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.086{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA458ACFFFC48AB56195D327D660D4EF,SHA256=60A81A7750079698A8639E5E5B1208B6F741350E20A1E596BB4FB9846046C87B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044123Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.347{323FE7D8-19F9-6136-CB08-00000000F001}20964024C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044122Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19F9-6136-CB08-00000000F001}2096C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044121Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044120Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044119Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044118Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044117Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-19F9-6136-CB08-00000000F001}2096C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044116Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.110{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19F9-6136-CB08-00000000F001}2096C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044115Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.111{323FE7D8-19F9-6136-CB08-00000000F001}2096C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044137Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:06.563{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=336FC13A5539EE5F872243FF73ED2AC5,SHA256=DD8624772D672437A4049FF4C4543DD935DFE718D08189BCF4CC9EBE97738721,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044136Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:03.803{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51614-false10.0.1.12-8000- 23542300x800000000000000044135Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:06.409{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=276C863960A028CD747E663699CFC8F0,SHA256=AFBDA88EDDD46D5A99B3E3F464D650730D34614DA9C91E11554DA1BFEB52A5AF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025234Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.602{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=AD07E7B56BB7961790A1258D7887C9B1,SHA256=57BB0D497180B73482C575E87B25EEEC49B7F653209D1260E968B32AF8CE00C5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025233Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.602{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0619863F85EF8A8BD6141E608A1F8F30,SHA256=D691EE37C4523048B187BD780AD14D69A7452C0BA1D74F852EA0D9066DD16649,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025232Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.602{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=225401A707EDF600FF161863B2DB2663,SHA256=055C57BE7FF71F05B8CAD8CCF67CFA2455848BF502AA39B1438D6EE466346B65,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025231Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19FA-6136-4506-00000000F101}104C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025230Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025229Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025228Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025227Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025226Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025225Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025224Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025223Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025222Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025221Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-19FA-6136-4506-00000000F101}104C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025220Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.477{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19FA-6136-4506-00000000F101}104C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025219Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:06.478{FFF7FB96-19FA-6136-4506-00000000F101}104C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025218Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.993{FFF7FB96-19F9-6136-4406-00000000F101}676516C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000025250Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.743{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C09C1FC056545FAF44E4C365357788E,SHA256=EE99673CEAF67356925DBDE6641D3FDEC770D28F467CD075444112F82CB14EDE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025249Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.743{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=AD07E7B56BB7961790A1258D7887C9B1,SHA256=57BB0D497180B73482C575E87B25EEEC49B7F653209D1260E968B32AF8CE00C5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025248Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.539{FFF7FB96-19FB-6136-4606-00000000F101}37723228C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044148Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19FB-6136-CD08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044147Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044146Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044145Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044144Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044143Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-19FB-6136-CD08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044142Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.946{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19FB-6136-CD08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044141Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.947{323FE7D8-19FB-6136-CD08-00000000F001}4932C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000044140Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.157{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51615-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000044139Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:05.157{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51615-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 23542300x800000000000000044138Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:07.427{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0998FDEBD0A336C93E3CA7BE2CC301A0,SHA256=E52E557B96EA1F9BA688C764E6F5155B738534CD09529711151EFD7A1074F6BE,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025247Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19FB-6136-4606-00000000F101}3772C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025246Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025245Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025244Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025243Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025242Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025241Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025240Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025239Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025238Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025237Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-19FB-6136-4606-00000000F101}3772C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025236Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.383{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19FB-6136-4606-00000000F101}3772C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025235Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.384{FFF7FB96-19FB-6136-4606-00000000F101}3772C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025280Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.852{FFF7FB96-19FC-6136-4806-00000000F101}16283268C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025279Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19FC-6136-4806-00000000F101}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025278Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025277Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025276Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025275Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025274Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025273Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025272Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025271Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025270Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025269Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-19FC-6136-4806-00000000F101}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025268Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.727{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19FC-6136-4806-00000000F101}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025267Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.728{FFF7FB96-19FC-6136-4806-00000000F101}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025266Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.540{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15D941E753AD22CD8E9008F53BABEB3D,SHA256=F4807CAE721EF6510BE9A29F54C22535E13C459543C017DB341FF25F9F5E744D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044160Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.947{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=32D8321B6F508F5F2B371451840B39D4,SHA256=BF3672A3839B441712ECB62B0E52D82A92872365D1AF1E4C8289AC7A313368BF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044159Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.730{323FE7D8-19FC-6136-CE08-00000000F001}4624696C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044158Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19FC-6136-CE08-00000000F001}4624C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044157Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044156Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044155Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044154Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044153Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-19FC-6136-CE08-00000000F001}4624C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044152Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.562{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19FC-6136-CE08-00000000F001}4624C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044151Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.563{323FE7D8-19FC-6136-CE08-00000000F001}4624C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044150Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.446{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F6FD9913EA57FD08E791CE9F119FEF76,SHA256=FFC1F6E542B85231A48E5E8CBD577711E3C7512B57BFBFB6366E7010E0597F27,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025265Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.196{FFF7FB96-19FC-6136-4706-00000000F101}3844720C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000025264Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:05.480{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50872-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 10341000x800000000000000025263Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19FC-6136-4706-00000000F101}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025262Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025261Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025260Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025259Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025258Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025257Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025256Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025255Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025254Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025253Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19FC-6136-4706-00000000F101}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025252Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.055{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19FC-6136-4706-00000000F101}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025251Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:08.056{FFF7FB96-19FC-6136-4706-00000000F101}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044149Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:08.131{323FE7D8-19FB-6136-CD08-00000000F001}49325280C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000025295Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.758{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26FF340CD1524EDE69A5CA3C3A7ACCA9,SHA256=F74BDB05011F48C1F2F59E4C62D3D8B4F6C0FC1A3401B5DB78D0B05C79E7D632,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044178Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19FD-6136-D008-00000000F001}2340C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044177Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044176Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044175Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044174Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044173Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-19FD-6136-D008-00000000F001}2340C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044172Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.847{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19FD-6136-D008-00000000F001}2340C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044171Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.848{323FE7D8-19FD-6136-D008-00000000F001}2340C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044170Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.462{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CEF435BC49CADBEC218104FA04D4831C,SHA256=DA2A168944A015318BF4F7E16BB5EEEF67073C1B12DD46430EB052C446CD794A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025294Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-19FD-6136-4906-00000000F101}348C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025293Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025292Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025291Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025290Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025289Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025288Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025287Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025286Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025285Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025284Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-19FD-6136-4906-00000000F101}348C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025283Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.399{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-19FD-6136-4906-00000000F101}348C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025282Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.400{FFF7FB96-19FD-6136-4906-00000000F101}348C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025281Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:09.102{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4860454B15726DC33036F87A1D2FEADA,SHA256=48609FEDC63C2FD21ECC3E2AC5E589ECF2F0C2A2E66056369093A9D3362BC213,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044169Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.331{323FE7D8-19FD-6136-CF08-00000000F001}62405792C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044168Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-19FD-6136-CF08-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044167Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044166Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044165Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044164Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044163Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-19FD-6136-CF08-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044162Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.162{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-19FD-6136-CF08-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044161Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.163{323FE7D8-19FD-6136-CF08-00000000F001}6240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025298Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:10.993{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9DB592F0DAE85FDAFE615D94FE300EA,SHA256=24472894D1A9BD3674BE52AC3A84D3AB54CAD7B0712F39225D104EB5B68232FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044180Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:10.462{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A2061B21F00E9DE7841638F1C3FB96B,SHA256=9E9A3C874717E7D4F044E4416BA621F8D2638A9EBAB58DBFD6EFDC2FE4464DAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025297Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:10.633{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0B96927AA869F0725772E65FDF427590,SHA256=31355AAAD46BFBBCD1919257893BD984581A23AB58174047C6D00D7883A4CEFA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025296Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:07.933{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50873-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044179Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:10.163{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=67AD5B53D6D849ABE49434D0A758F481,SHA256=EE3CF92D44BD93BEBFC9DDCC6596F9B6C3189806AE56E5BB892A66ED798FDF29,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025299Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:11.994{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C73E65CA1E8740D9C51F614428E81E99,SHA256=729DDD473202D06AD2989A75C33A8250554A96813560545844CD6F1D3BA173CA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044220Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.777{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D85F953A4AF8B40A7BE22B861A01234,SHA256=21100488692A4160418A042E52E2DF94EE4F5333F931AFF81786A818EB920C5C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044219Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044218Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044217Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044216Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044215Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044214Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044213Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044212Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044211Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044210Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044209Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044208Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044207Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044206Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2D00-00000000F001}1684C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044205Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2D00-00000000F001}1684C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044204Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044203Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044202Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044201Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044200Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044199Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044198Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044197Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044196Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044195Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044194Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044193Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044192Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044191Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044190Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044189Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044188Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044187Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044186Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044185Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044184Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044183Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044182Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044181Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:11.293{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044222Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:12.792{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA30782417A4F8D8844E5D031052FBCA,SHA256=94B1DCA486FA86FAD9B78F26964E4C31C5699148570147D6424D41D542686180,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025300Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:12.453{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-090MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044221Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:09.703{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51616-false10.0.1.12-8000- 23542300x800000000000000044223Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:13.808{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=60C13CAE8E00815459DBECA9C9BB895C,SHA256=94B11BC495C857B3A47AA08B364A427BBE0D0CC8D886BC313759DBF609154978,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025302Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:13.450{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-091MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025301Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:13.012{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F174CFB2388B8A3E0FA61D1E292A2C0,SHA256=0B889909D53D46D30F34FC7DE50F317B0BA75003154A52733C7940E33B708FC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044224Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:14.824{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=57560F2BCB7B5C6E68713B72DEB55644,SHA256=55B26FB585C0E1B994A7E36F4918B78FAF4D5E56E029B0A2DCBF9ACF964F5465,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025303Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:14.028{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=972F0BA416224E20BDE17C62EA538395,SHA256=C329672516054C4D76CCB3F94F5FE617AF9A2C71D84B4C05C52A4008B047933C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044225Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:15.843{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD15DE83CCA48CB988D8E048E0E23A55,SHA256=C177C7949123E49FF78BF8A949AE6876818659CA515993E5A44EB3F09B0EDAEB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025305Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:12.952{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50874-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025304Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:15.043{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3294E0DF896C7860994EF633A0890267,SHA256=EC8FFBBF553D1B8F836641DCDBB4BCB86DD8F6B165A14E73B7467D2FDAD60466,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044227Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:16.858{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DA033896D5F5C7817C4AACE114C65A6,SHA256=E409FCF9262902B8D0A569C913270EAC51E8E37B1EEB67DD41452A7AD55F8F58,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025306Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:16.090{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEE9DF86300B930DF6132F7CC1B61FCE,SHA256=265AF717691B4530269310412B6A5651DBF6DBA8D0B16616B794B324781A0AA9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044226Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:14.715{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51617-false10.0.1.12-8000- 23542300x800000000000000044228Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:17.873{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FBD88FCCB84484FD654ABDFFE056E60A,SHA256=3EE438040618861854E467B228468195027322F43D037789AEA94279A4214EE2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025307Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:17.121{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F4F276FA2E01E7D82346D0281D15874,SHA256=E778201111AF7D4665DE72A626C8B29636221A7EEB82BFA865CE8CF693B444D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044229Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:18.888{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C63F775EF6AA64B5351A753CE898356E,SHA256=2E0D5D524CE9CC8842F276428F3C398B9B4D3D515ADB6E9348283C245FB3E684,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025308Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:18.121{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8BAE68AAF311764BE71DDB44990B632F,SHA256=880B0D053BF3E9EE176C251C7AAF9D37B24E25C152D24144A0D0E338CE0305AC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044232Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:19.903{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08689BAD89AC11C783A55AC554FDA829,SHA256=785697BCED64FDD0A5888A424787529085718256BD196DC361A3D4D6291E6AAF,IMPHASH=00000000000000000000000000000000falsetrue 11241100x800000000000000044231Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:19.321{323FE7D8-0617-6136-F403-00000000F001}4476C:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\SiteSecurityServiceState.txt2021-09-06 12:19:19.165 23542300x800000000000000044230Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:19.320{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\SiteSecurityServiceState.txtMD5=129544CA9151380E3AA885B74D327586,SHA256=48811B868A708251D7B85DC48EDD419D412FF791E9EF5A71940979F8F52C59FB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025309Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:19.132{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4E4A8CDAA180DB456A70BE5263E29109,SHA256=329626D9254AD0E7233EF86572EE1ADA4CA883CB076AD886DD6BA8F4EA3293DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044233Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:20.920{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F2EC057856760CC66E61BF68E841F29,SHA256=685B4941AFEEDE5079BA4F264F7A8F12EFA7C199D9FAE1909084ABBAF2A28270,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025311Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:18.030{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50875-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025310Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:20.163{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1246BA768854BB20493D9FAE824E3D88,SHA256=EE725E43B172972B6A1F6F5E333FF8B31A46E3AA425871FF20232F9EF6F8900A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044234Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:21.939{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE68443F0828D8E4EB5609E26F68317E,SHA256=872B2AEEF6ABA35D5471FC1B440498A10DF039D571CDDC75DEBFA58FBFCE39A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025312Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:21.210{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2C90BA9919050AD585D934826E2FD84,SHA256=CBD5E88C2FE0A4210A3057580476909C41AEC6E957532212A5CD33CE261D7BC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044236Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:22.954{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=934A4621DD23A96DDCA36203E2430734,SHA256=260B707845DDB15446E7FAC6A323CAA0623438D9439302F34026156D3FBC392D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025313Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:22.210{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED579FEBB90D7EE28C19671B49F46CBB,SHA256=9789798DDAEB8C522D5B372B157A23EE2E8439908DF30FF431A024AE2172102B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044235Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:20.649{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51618-false10.0.1.12-8000- 23542300x800000000000000044237Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:23.985{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B50EE7B947D35EC815BF6B14F11E3E90,SHA256=06C3C7EB97EF764B2F273B18AFA3EB14811C21F18B12C1B4E05D2F7415DFF66C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025314Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:23.210{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4922C804533ABCECA776144B92590D80,SHA256=87CB53EF218ECCE46171B02249B408D038D1E21F89B76FDFD3D0C5B38C02A4D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025315Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:24.226{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06993AE34B267DA9AFF20508C8BCC832,SHA256=0EA5D63603A631E716FDFC99D270BA4176076FA3DF8013798C14B3E6617F570D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044238Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:24.088{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-098MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025317Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:23.947{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50876-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025316Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:25.241{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C550DADB3A3B41E5529EC0D3BA1A364A,SHA256=2F9C22F332DE9AD835B2A73E72ADD79903B3A4B3FD74B85D475330922EFCA034,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044240Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:25.101{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-099MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044239Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:25.018{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1BD8A3802FEE6090FC066958EE1537EE,SHA256=6C0FBC0EC6B5FE83236DD6FFD78EC3BD69071D8C24C2F63E69001792E44C2565,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025318Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:26.257{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=882C601A9647CEDFE75FA75D81BC8FBF,SHA256=105CCC1EB8F310A69DA8DE7D9707F2669EB71CC212047825CDDC7925BA6F562C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044241Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:26.037{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=81B6380D55656BC6174FA42EB02DFE0A,SHA256=7DF34DCDDB04427B0E77A044B04AB41CA904F8187BDEE0A2EBA514ED1AD6B08E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025319Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:27.257{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B71F8E3069D26275DE519FC436B087B7,SHA256=0CECB04B820E35D4D8C37554292665723050850022CF88FAF0607F535562362D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044242Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:27.052{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1494F852C07EDB33BAA7B4DA1F2F891E,SHA256=43714316099DC7EC5475600278D1A0CB65B38EE59EF7C144481443A1D5891C59,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025320Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:28.257{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=463EC835A56D9B63B29B58906C9811F4,SHA256=F7AD9601BB26D8362DFA597F045696AFC97ADFBF2E1DAA1F415F29ED43E7A548,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044244Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:28.067{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2ED8D135225FEA3980B444C000F968D,SHA256=03D78ED4B6B8CC8DA76C11248CE19E68E668FCCA03E9FDF7D40DFCFAB0A914E3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044243Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:25.709{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51619-false10.0.1.12-8000- 23542300x800000000000000025321Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:29.273{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1686FA6CDE910A10FA57C8732C34E7D2,SHA256=2BC260B9DB73302BA603C153BD854D5E8AE47B634D6E04DD6C5268216DB9631B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044245Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:29.098{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C2AA9FB877D30EB7C9E275D83D522D8,SHA256=F9EC0039A9E3D1C02A39714BE30464DB5E711790C4886663593B241293516FDC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025323Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:29.010{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50877-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025322Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:30.273{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FEB0E8DBE6051FFC48B8B5D16525B42A,SHA256=88DC5CD82571D03499DDDB824B56D7659F33D77505DABD47D48B46F376A3B6A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044247Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:30.172{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044246Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:30.116{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9AF3306A480AE47D6FCAD712F67A3345,SHA256=A08437ED4D5D466042908B6965B63E73A3BB54C4FAC84EDACFFF5C5AA08885C5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025324Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:31.288{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F4EFE9FE557BD9B3008F0FDDE1115931,SHA256=B7979CD8FBAA874ED301CF2F4772BDE61B95E43C30757B9B2B10F78A4A2AF54C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044251Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:31.988{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044250Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:31.988{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmMD5=7A5884BE61DB4033954E834E6F59F75E,SHA256=01F29F5D8FC580E218A8DFB6B6E2B23BF4C68126768A6EF219DF26C063FFF554,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044249Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:29.750{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51620-false10.0.1.12-8089- 23542300x800000000000000044248Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:31.122{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F2EA78B511AD1635804EEB7BEDEC49B,SHA256=5F8350FB4D98FBACB4D3BBEF2C0969E7BD9C78E1B132B22837BD68F21AEFFC1F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025325Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:32.288{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B3E9501B1D678BA428CC2890023F044,SHA256=F3EEEABC65A6946B82C5AEF0B6C349FF9EDD1BBC786990051430CC9DCE9958D2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044253Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:30.813{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51621-false10.0.1.12-8000- 23542300x800000000000000044252Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:32.141{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4558CEC08D5468A09BEB46446DB4A376,SHA256=677FFBF69EF1F580CBD6E292F979CE79A3FD9FAC21C787BFE6905CF136D5D327,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025326Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:33.304{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE3E593B8C51BA71C83EA856080D3CDB,SHA256=EDA9F06F4EF8C6017B6F339EB5D4570A51607D4F3CCDA71A860E30A49DB4A7C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044254Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:33.155{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FAAC73243065AD11BB1575D3347AC623,SHA256=DCCE76697FE8DF77E092BCDC542630B5EF443EA7C8F96C4A2041BA9332E81C6B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025327Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:34.304{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E26AB7291D9B54509A4B892883743518,SHA256=7280A933A23DEABE5CBBB4994A4F409873EF55F7D0C1C4ACD8A53C507431A2FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044255Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:34.171{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=559A325DB6A758000D8469ABE6DE98F3,SHA256=34B26F33D03B1FAB99F486BC7BEF0CA57D129BAB6F2164F9D349EFFB019B4122,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044256Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:35.185{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F64EAC08A92F8CBCFB071156CFDDC128,SHA256=45DD9BC4A1C08B9F3C1BBA2C665A00DAD9AE48C6D1F0F46461F66EF85D8552BD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025328Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:35.319{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD31BD7D8F68542BA167279629F8FB6E,SHA256=ACD32C97947D733B993C59CC68B41617D7A299FA1D987F5131C9B09308E7CF71,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025329Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:36.335{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=407A691CC5008BC58B7E04BE0D6C42D5,SHA256=24D99E36A0B2233B39EC352CAF25D42E1DC69B518DD1210DF46D016B1DEC4792,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044258Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:36.200{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F7B5DD761B82EE0638A7E5A0066BA094,SHA256=2436627EE4BB4E38F66DAA59BBCC06C109FDFC321B6EBE754AB2F9530EC5869B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044257Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:36.200{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=D298CC8001EB169F98CC2E6D3C406489,SHA256=FB1AFA870ED152BBB6A3A63F9B5ACE0390DABE6D45B41E0B9A0A548D70EAC34C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025331Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:37.351{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F176539A44DB306E3D24016B5A7ECFC,SHA256=6D3B69CD66EAF8EE3D7E28DD960A25DB43FF166CF0CBCE94F639620BC5F156D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044259Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:37.218{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=477CF728A98F2E9F2A9BAC0D6AC4EFCC,SHA256=4C41EFC1AADD12EE0EF3AF7FB1A5D3F596631053458A4749FC2DF95D47B320E7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025330Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:34.900{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50878-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025332Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:38.366{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC1C2401BD555EEB92EEA8CF552DBC23,SHA256=7A64E3571A60CF9D8EC5994F5A8B3B0597C78ADD8A423C14D98B0441EF9C9CB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044260Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:38.238{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76AC6B50076048615AFDEF947F160FC1,SHA256=A92F56AA5AF9ED6E26AE06813BDA20C28E09F6A5846A95E086646BC277B633CB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044262Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:39.253{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F56A0911EB954710853712B3A734D65,SHA256=734792539CA277EF524E728E6C9011C02A9AEDB5C8E0206D19F3CDA951B2626D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025333Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:39.367{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=483C5D5070A02065893B0E9CAA07CD9B,SHA256=9A235105F9F8C814ED3D368059312B74992B888837E0F37B4106A5D8AE423CD8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044261Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:36.593{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51622-false10.0.1.12-8000- 23542300x800000000000000025334Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:40.367{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2CFC10AFE89D1C6BD0B557F55DDD424,SHA256=5DD05EE3206AFCB4E43D1FD299967505239CE4EF2EDE2160637100DD396AA4FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044263Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:40.268{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F43E2169C52F0C1E411A873428774175,SHA256=158A0ECFEBBDCA5742282202A3B4F7371D0744E910B1D969FCC7DD39469D9700,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025335Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:41.383{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=788991A986C3BCAE0A75469E30CEE59E,SHA256=F9FEBBC91421A449C4F946F1A11062E9F5B43C160B82472C3C337FCCF12E6438,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044264Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:41.283{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D02994ABAC18CD1316761088A1D374C,SHA256=E3A5B11E224CD9895401137D22D7F217EA429951A381EE28E03A8C902D382257,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025337Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:42.383{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=691DD2074B2D632DF73615A5B0B68F16,SHA256=12BE87D3D5CA3A4C17C075806C21ED20EB9A3ED5502CEFDF55DFD2C8B17B0563,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044265Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:42.298{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6102F4380423A3D6BB52225277966F51,SHA256=215E5A5814F66FAB8B32D3CE52BBB5A2744226788504A64540CEED8A8DF57476,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025336Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:39.932{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50879-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044266Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:43.315{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21D1B997FCFD3B1D762375E5383F7534,SHA256=57D79B635D75A2F68F93C19B7D5F5AB56D60F9EF8FC97BB328EF44BDEEA6D0E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025338Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:43.383{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C446A489C683841BE1CD08014638BBA,SHA256=2C19B069378A810F5BFE4933463AA7F9B0BD586ADB9F86EA844205AE46788A3A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044268Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:41.760{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51623-false10.0.1.12-8000- 23542300x800000000000000044267Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:44.334{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=70DA0E979758284EF6C49039AC223A20,SHA256=35A2B69E137556291ACF39AD06A9DFB61335AA693B2A513FAF33D44CE2CEED5D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025339Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:44.398{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CAE2F87D8626DF4FB4EF46E170437B29,SHA256=081A32F6A8C8B0BC1AF573F657E497EC52C78E3FA9BBACE25C614BF8B65875F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025340Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:45.414{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=420DF6D86CD96D553816769F4BA5F3C2,SHA256=A8CC5EE09A0AE93D7A01B530913DFE9D4A312FE14803723A945F5842AD0D15D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044269Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:45.349{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2EDCA407433B79D5C35B1C135276A194,SHA256=CA67F13E683B55550601636C28254E5B58594D32E7015D420B38FCF2C0074995,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025342Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:46.430{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E04E2FE69F338F84291E7D45ED2603E,SHA256=D0318B1A41FF9E644B7AB7D3B92ED1AEFA7A8D5CC1606F0C8D5C6883EABB309E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044270Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:46.363{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=47FBBEB4A61799EF9B617D4CE574EFEB,SHA256=2A5A30BFF571C3E757F1006370ACF0FC90152AF40714A20E45F20335A2BB36C4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025341Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:44.932{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50880-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044271Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:47.378{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C49A3DAAC439714DCB33DD10E2F29681,SHA256=C21D8E597845D42FA17CA4C52DE60E91B8F8CAE794473EA5F17D64E17649D9ED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025343Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:47.445{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D40CE1C38BD43738FB52199DDA2BA43B,SHA256=4CBC7582EF2C65D9D349B37F1DBAA81C1A357A93E475B256C259688A9B0257FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044272Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:48.393{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC2E9B339E3B998700624F553B334B8B,SHA256=0BA08822C26BDE215F47CBF2F6CEB4B5F8AE73678E43AF0825EDE23B67A0710C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025344Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:48.445{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=947D07CD08BD0B9287AF65DE8F30E135,SHA256=98DCEE7C815B87EAEBAAC74817228E024E634FD194E32BF4D27F1C8257F725E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025345Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:49.461{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39ED5BF641CC121758F737D831B2467A,SHA256=A198DE932E2A671C504F5CEF7B26D43A1A7BE3AD1E5E3C6C8A404F67B2369290,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044273Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:49.411{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9077D845692D7C22D202B85DCC66E71F,SHA256=0A6E3DDC506D8B94082E42280D72365C2F4E42C9C5062EDBA86AA7F75F26D5A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025346Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:50.461{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84ED829FF8102AD583A96E88B32072E1,SHA256=FD4251B76A688138576B6DBD29231D230A3781272E3B476B80A99559AD902CCE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044275Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:50.431{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0419E111FF466C5DCCF521A6D9248690,SHA256=7171498036E37A7899CEDFD6FA6BC2D794589F40AEAB9626316F76877A0ABF3E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044274Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:47.802{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51624-false10.0.1.12-8000- 23542300x800000000000000025348Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:51.586{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=B30CBB7EFF2C0705E6799C2DD66C6110,SHA256=7AEECC8A4144FBA100AF546C2AC4514F6F4B0CF51CDD7AFBD453E5E0B5927336,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025347Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:51.476{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C174F2B440EBE3ACDAED026A8B437F60,SHA256=0686279C2C5D6C418CAFAA881FD256E27FC030C9CC285C807923FF115D6EF044,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044276Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:51.461{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=212D6B92C628EFDBA7FF686D928A5107,SHA256=C993E83C718DE6A02D723EB4013A8DDC8387337BC7C6FD7C6DD3070D12616592,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000025360Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000025359Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x00562846) 13241300x800000000000000025358Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7a31c-0x49a9478e) 13241300x800000000000000025357Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7a324-0xab6daf8e) 13241300x800000000000000025356Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7a32d-0x0d32178e) 13241300x800000000000000025355Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000025354Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x00562846) 13241300x800000000000000025353Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7a31c-0x49a9478e) 13241300x800000000000000025352Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7a324-0xab6daf8e) 13241300x800000000000000025351Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:39:52.820{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7a32d-0x0d32178e) 23542300x800000000000000025350Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:52.476{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CCEE1E5C88B6ADAE37902E4770492572,SHA256=C1FDBF3CC6895AF2B46BA854290677832D25F0B582B0F24C57D3872D502B681F,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000044278Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:39:52.729{323FE7D8-022E-6136-1100-00000000F001}492C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7a324-0xabce5b00) 23542300x800000000000000044277Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:52.492{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6875B7BB237F3D0F228A1C4BE7FEC9A5,SHA256=7B8AAD4B9FB675CC2501C27955349E572144085FB321BB34F714E825CC2850BA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025349Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:50.963{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50881-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025361Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:53.476{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50837E7FD053BCE7400A6083373CFC1D,SHA256=A13B497A36E930AC7EE9AB71A679F5D4F93673F3A1D1E6B53E5EC2B1229B439E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044279Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:53.529{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C0E1B9CB0666D3998A3C63BDB7637788,SHA256=A32230C44261B6ACC23070D6D0208BFFEF25E8EE9FEC032AEC75226D32BB7E47,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044280Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:54.529{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD5E3A869A9FAC830D82B48A442CA3EA,SHA256=433E0698F3010189FFE3F314EDA09C0A93C5F973CBA4C0D7AE9DD96475AF02FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025362Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:54.476{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC245EFE28EC2281BBB4C2058A444A9B,SHA256=2754DAA766A4294DBC6DA9E1D126AED85D94CBFACBDD531AEB781335EDA58833,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044282Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:55.544{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4064EC2C2D7183F1D3443DC41A80420D,SHA256=3BDD59FDCF903036DCD834FB90EDC7E11BE25910A0B1ED43397E8CF6A938E690,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025363Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:55.492{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=916F3C8FA31D02BD3C843D126848F006,SHA256=7848F3D3A195BD87D23C49763E9CD282F8F3B0B4E6AC653E21373365E7BAD31C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044281Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:52.300{323FE7D8-022E-6136-1100-00000000F001}492C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.14win-dc-456.attackrange.local123ntpfalse20.101.57.9-123ntp 23542300x800000000000000025364Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:56.492{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8CA09577A12FE503C56E9E475DCBB73,SHA256=F17B298999ABAF7A6AD6587F1303A7DF7BA43E352636AA39D265FFF48701057F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044284Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:56.559{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=61CBFD87D55CB340A248A572668F00FE,SHA256=ED259D9EA39C65826A643F2CE3485E86D14983EA63E2049C8B0837C8A7E721F0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044283Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:53.738{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51625-false10.0.1.12-8000- 23542300x800000000000000025366Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:57.508{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6475D9625A2AFA94A2131F6246CA6C30,SHA256=40F9042DAE8BECD6EBCE71A237949CFF4ED3EFE810661B798E0D2E86807B60AA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044285Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:57.574{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DC292A031514EE556B3F96CEE04846B,SHA256=E1A82C8A3C873BFA342F0D9675D696140CE3BBF15F7843B0393830DD8CEA7B40,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025365Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:55.964{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50882-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044290Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:58.608{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AB125C0283E3C022FA55DDEE548F60D,SHA256=2FBA5628C0FF66A73000726BF5B3FBBECEBC944FFE04EF818952296CF5AAC986,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025367Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:58.523{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=056A4E89F569A89C6CDBB466298A7295,SHA256=8044C1985FB2523413260161B9AD7BCFE907DD3E7EC9982FF921A952D2B544D3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044289Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:55.989{323FE7D8-023F-6136-2E00-00000000F001}1500C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-456.attackrange.local53domainfalse10.0.1.14win-dc-456.attackrange.local58955- 354300x800000000000000044288Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:55.988{323FE7D8-023F-6136-2E00-00000000F001}1500C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-456.attackrange.local53domainfalse10.0.1.14win-dc-456.attackrange.local55566- 354300x800000000000000044287Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:55.987{323FE7D8-023F-6136-2E00-00000000F001}1500C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local56711- 354300x800000000000000044286Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:55.987{323FE7D8-023F-6136-2E00-00000000F001}1500C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local58294- 23542300x800000000000000044291Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:59.641{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6771ECAA2155391E79222E9DC40025A4,SHA256=87C43E171DF331F5E7F95440543DE7E8ACA56E2FD2A9F9253045EB3F194748F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025368Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:39:59.528{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6DCBE91C6671FB976E95B240CE1F1EA4,SHA256=DD4C33487ED462A898A36EE91B7A5DFFD68DD28153BB70696F1B6E811024D443,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044292Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:00.672{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6AC9CD7D657AA33504094335A33FF2D0,SHA256=0DA0FD8ECA24B393DA8B206D924DFDEE895476DED1479846F1C28393ABBCB8EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025369Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:00.528{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FDAFD20D812A8868A93B4D839A86B99,SHA256=3C0FDE7053AA4C2C5D3BF3ABB7AE8741F1DD97B20D5A4A3FB8BA325DCCE9961C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025370Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:01.528{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26D0E30918EE235D5F5D7FBEB39BC174,SHA256=F22C16DCA85D50A069CB1A745D159E31B3EA85286868D1369FBDEC36076DFA31,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044294Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:01.687{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC7EEED34643E6A468D06A1CD4A155C3,SHA256=2B09C88B425E014F40425A05196FD0183B942640F88BE7E6E120016FCEA63AB2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044293Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:39:59.750{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51626-false10.0.1.12-8000- 23542300x800000000000000044295Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:02.692{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD3EB9BFF0FD89AF6F6079DE7CD0C9BD,SHA256=F4B5562A7A7FA3A49BCD237172858903748C9D290E2C0154A081B9A1369DEF90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025371Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:02.528{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D218FE3404B800C0FAFBC044A5A2BBB4,SHA256=3174CD01DBCF7DFD3AC372294E2C1A1A9378423346EBF8A01E58893DDF59C7A7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044296Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:03.710{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0FDEB1EA4CFB6F6D729A7550FB779DA6,SHA256=A93B82A14B4ABE3484757A8E9DB162F07E0D1949DF4A52DDE9C4CA8AEF2841F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025372Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:03.544{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E86D2B27B9093B0B285B60471F18ED5,SHA256=B7188F910397F6F6167C68F31892641F8793795DA7A198086082D136CCF1B761,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025374Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:01.937{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50883-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025373Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:04.544{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FA342750E872FA2F9DE87FEB10F56627,SHA256=5943B8ACAA2A4BFA97175DEEF6F333FAD9D3650A3595A02F6E31B187082DA36E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044306Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.729{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=341FB183879136710E3FFF3BD44F857D,SHA256=106D969953FEE60BC0BE71DA838146835867F6AE06A4D49956B4A0419D964EE2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044305Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.628{323FE7D8-1A34-6136-D108-00000000F001}61243360C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044304Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A34-6136-D108-00000000F001}6124C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044303Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044302Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044301Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044300Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044299Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1A34-6136-D108-00000000F001}6124C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044298Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.428{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A34-6136-D108-00000000F001}6124C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044297Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.429{323FE7D8-1A34-6136-D108-00000000F001}6124C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044325Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.744{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0CED3A795D650B415E3C6624E7A98703,SHA256=77555A8475C0B23B37FBF00CF7850D27939F5FBB5CECBBBC9F2FB4434BFFCD32,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025403Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.965{FFF7FB96-1A35-6136-4B06-00000000F101}24122392C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025402Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A35-6136-4B06-00000000F101}2412C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025401Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025400Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025399Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025398Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025397Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025396Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025395Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025394Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025393Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025392Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1A35-6136-4B06-00000000F101}2412C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025391Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.809{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A35-6136-4B06-00000000F101}2412C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025390Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.810{FFF7FB96-1A35-6136-4B06-00000000F101}2412C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025389Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.669{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025388Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.544{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=40E2878F3C7A254B2335B78BE58B96CB,SHA256=335DA7701CABEFDB1C58ABAC15CEB52A73CA28FC86518DB92557273523F62326,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025387Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A35-6136-4A06-00000000F101}2292C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025386Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025385Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025384Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025383Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025382Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025381Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025380Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025379Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025378Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025377Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A35-6136-4A06-00000000F101}2292C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025376Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.137{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A35-6136-4A06-00000000F101}2292C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025375Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.138{FFF7FB96-1A35-6136-4A06-00000000F101}2292C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044324Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.612{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A35-6136-D308-00000000F001}5296C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044323Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.610{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044322Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.609{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044321Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.609{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044320Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.609{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044319Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.609{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1A35-6136-D308-00000000F001}5296C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044318Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.608{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A35-6136-D308-00000000F001}5296C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044317Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.608{323FE7D8-1A35-6136-D308-00000000F001}5296C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044316Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.429{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A66650AAC9A6C1BABA4F328CFE89AD7,SHA256=CF6E059690FACA96E9F9CA5F469F6C6EEB75A4BD3CC7DEA7B1FEA6FCC83931C2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044315Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.429{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FB052D71DC62553683649A895B814259,SHA256=71EEB156943D7B60C418E08F6AFC8FEFBF8CC07E8612FCE2BD1EE0A97767F45B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044314Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.013{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A35-6136-D208-00000000F001}4148C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044313Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.011{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044312Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.011{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044311Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.010{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044310Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.010{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044309Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.010{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1A35-6136-D208-00000000F001}4148C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044308Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.009{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A35-6136-D208-00000000F001}4148C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044307Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.009{323FE7D8-1A35-6136-D208-00000000F001}4148C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044328Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:06.759{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0D2B0D62D1F7CF5FFF4F5B42760581B,SHA256=86315D639EA1C2572B88B15855FBE9A32740D279C79526BA8B04E61E815BF59A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025419Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.590{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8DB8569714682542E86CECE82893427,SHA256=B49C6C45E16440E53B288985AE0AAA03FDEF2A85D36B6CAB9F9A1C6AABEF86FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044327Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:06.591{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A66650AAC9A6C1BABA4F328CFE89AD7,SHA256=CF6E059690FACA96E9F9CA5F469F6C6EEB75A4BD3CC7DEA7B1FEA6FCC83931C2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044326Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:04.769{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51627-false10.0.1.12-8000- 10341000x800000000000000025418Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A36-6136-4C06-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025417Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025416Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025415Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025414Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025413Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025412Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025411Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025410Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025409Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025408Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A36-6136-4C06-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025407Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.481{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A36-6136-4C06-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025406Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.482{FFF7FB96-1A36-6136-4C06-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025405Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.153{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FE9E1DD7A6BEA284EB88963F90CC02A4,SHA256=84204A92BF8221225D1E9C1F0095C20EC485202A911FC562AD32D8F2C5AEB44C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025404Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:06.153{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3675892FB11F036DD0252271E8D9DF07,SHA256=4DD04ADD215255CA867C08F27669A8EE706422951A28B4538BD47422E94F15CC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044339Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A37-6136-D408-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044338Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044337Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044336Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044335Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044334Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1A37-6136-D408-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044333Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.958{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A37-6136-D408-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044332Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.959{323FE7D8-1A37-6136-D408-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044331Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:07.790{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A47C1D07063D3A46DC35258FFDFA1E12,SHA256=3E4C28E4F0AC96F6AB6FEEE0C9B1826B26EA6779A5C72233E689665FEC6B81F6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025436Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:05.500{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50884-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 23542300x800000000000000025435Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.591{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA3E24812855C2310BEA14BAFC2BAF35,SHA256=6F903955CC176A311AD186F61314D33ADD32A5B9C3C197D9A6340672986F9609,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044330Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.169{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51628-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000044329Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:05.169{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51628-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 10341000x800000000000000025434Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.559{FFF7FB96-1A37-6136-4D06-00000000F101}37643260C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000025433Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.544{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FE9E1DD7A6BEA284EB88963F90CC02A4,SHA256=84204A92BF8221225D1E9C1F0095C20EC485202A911FC562AD32D8F2C5AEB44C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025432Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A37-6136-4D06-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025431Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025430Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025429Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025428Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025427Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025426Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025425Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025424Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025423Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025422Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1A37-6136-4D06-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025421Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.387{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A37-6136-4D06-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025420Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.388{FFF7FB96-1A37-6136-4D06-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044351Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.978{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7E1720EC096C7809A6E08920748DBFA3,SHA256=C59D4B988F6610E8AB42004A31CDE03FC95225042AF23A262E4BBFA977EFB3FD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044350Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.848{323FE7D8-1A38-6136-D508-00000000F001}39563832C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044349Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.813{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B83206A07A7C4CAB140FAC65DBE00572,SHA256=BFD33ED2A8E4332031D7949B612F234669FEB5DCEDB8860CE360A94F1E50BCE5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025465Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.872{FFF7FB96-1A38-6136-4F06-00000000F101}17043296C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025464Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A38-6136-4F06-00000000F101}1704C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025463Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025462Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025461Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025460Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025459Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025458Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025457Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025456Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025455Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025454Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A38-6136-4F06-00000000F101}1704C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025453Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.731{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A38-6136-4F06-00000000F101}1704C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025452Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.732{FFF7FB96-1A38-6136-4F06-00000000F101}1704C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025451Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.591{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=19FF1031FACD68D0E6700C86DD0916D2,SHA256=F1DDB2624A3EFB1DE51804C5E33FB23226DBF5B291E48126ABD07C0C143C1063,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044348Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A38-6136-D508-00000000F001}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044347Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044346Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044345Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1A38-6136-D508-00000000F001}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044344Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044343Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044342Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.641{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A38-6136-D508-00000000F001}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044341Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.642{323FE7D8-1A38-6136-D508-00000000F001}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044340Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:08.237{323FE7D8-1A37-6136-D408-00000000F001}61281936C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025450Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.200{FFF7FB96-1A38-6136-4E06-00000000F101}2956500C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025449Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A38-6136-4E06-00000000F101}2956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025448Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025447Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025446Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025445Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025444Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025443Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025442Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025441Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025440Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025439Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1A38-6136-4E06-00000000F101}2956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025438Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.059{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A38-6136-4E06-00000000F101}2956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025437Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:08.060{FFF7FB96-1A38-6136-4E06-00000000F101}2956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044369Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.861{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A39-6136-D708-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044368Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.858{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044367Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.858{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044366Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.858{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044365Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.858{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044364Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.858{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1A39-6136-D708-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044363Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.857{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A39-6136-D708-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044362Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.857{323FE7D8-1A39-6136-D708-00000000F001}4628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044361Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.840{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC49C6C064B6A902B623414A4552D66D,SHA256=BD717C54C8B50849A63A23A28F3D3FFEBBD5B7DABB753C2AA34DCCBA8477D861,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025481Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.731{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=54251DA1536B3A5E24EBD5C50210799B,SHA256=09567417FBF4C5F3D7EDE33694CE96E1DCC2D09069BFD9C21A74F9BA86396AA1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025480Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:07.064{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50885-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000044360Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.340{323FE7D8-1A39-6136-D608-00000000F001}48166400C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044359Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.162{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A39-6136-D608-00000000F001}4816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044358Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.160{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044357Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.160{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044356Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.160{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044355Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.159{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044354Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.159{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1A39-6136-D608-00000000F001}4816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044353Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.159{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A39-6136-D608-00000000F001}4816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044352Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:09.158{323FE7D8-1A39-6136-D608-00000000F001}4816C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025479Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A39-6136-5006-00000000F101}3016C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025478Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025477Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025476Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025475Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025474Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025473Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025472Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025471Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025470Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025469Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1A39-6136-5006-00000000F101}3016C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025468Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.403{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A39-6136-5006-00000000F101}3016C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025467Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.404{FFF7FB96-1A39-6136-5006-00000000F101}3016C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025466Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:09.075{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B831C737A3049C8A2D46BB37A003890F,SHA256=5989EE30931D3102D94197BE90A1F7874795CD9D6CFC29375E66DE96947F4C58,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025483Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:10.684{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9CB2BFA692D13B3AD4D1E934B8BF9EBB,SHA256=2CC9F820A969CE44D3BA4533F89447C68F82CD4F5824D62ADB91143278F164AC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044371Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:10.877{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DD20B1233947EDA3CA2E62BA573671D,SHA256=604522FAF96C8E40ACC012E6B13047588B0568C23169DCBBBD16C7AD80AF0BCD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044370Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:10.177{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=ACC05609933212E5F884B0C0FF7936E4,SHA256=1A750A07CE4B149E4EB1E6F3535E7D21CFD53ABBAF39AF4D0F92408056C8A4CA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025482Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:10.450{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A599F4D11C5F2E773ECCA34BEEB1773,SHA256=7B0B25B5485AA7262A0972759DD8F840087F22FB02774CDAAF4B0CC0935617BC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025484Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:11.747{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7B980D731ECE29440577120F07602147,SHA256=4E6403569FD9A4481C8DC6E87295E9B6513E3D6B47B6EC8C85D1924850092B39,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044372Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:11.907{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9AE9B0F60BF9111025A73FD17BD80000,SHA256=A1E2049805C7585C1943F9111FB07DFC52DFEA36AE5D85AA34175F4A9D2F47E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025485Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:12.794{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=99BF1F7E2BD15866965CE3124AB7059A,SHA256=26916604DE711FA15086B2EC954CAAB4E036F5154C7283686DF919124A9E0DA1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044374Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:12.938{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=43F55E7C5D0305DA7C9D6F21BC778F5E,SHA256=1CA9C3509EB356804551F48EC1CF0C059807C0A7495D6040DC60A603B30F8233,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044373Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:10.717{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51629-false10.0.1.12-8000- 23542300x800000000000000044375Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:13.956{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=765FA337D213BD2F201DD33639677510,SHA256=0EC905EB39C098CA183AA8D138AA31016730D254D1DD8F7708EE43E710DD166C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025487Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:13.969{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-091MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025486Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:13.810{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C4AFA3611BFF4514C993C3C285444E3D,SHA256=2E4F3FA18BCA60B5C9A71E4969B8FFECF825F94088F86DA92B1A2149A2A35B42,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044376Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:14.974{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5E3EDC088C15B7C7C86A6F5D5EF5714,SHA256=CF093035E7C3DF40AEC18062CE89DC45053D79C0B97DC1AE32A23AB7DD91CBBC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025489Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:14.981{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-092MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025488Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:14.872{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C86F3D7DC78CBCB545A12D25F5A2D4C,SHA256=10B5A5A5359741BB9038F0C6675223FDF0A608D52893243525A957DDD9B801B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025491Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:15.892{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF95DC38FE25723A4A1ED7074B9BFC05,SHA256=773877A6BEEB355192E4F21C643552990EAF8BB8E703429B716779EC050CDFB3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025490Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:12.874{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50886-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025492Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:16.924{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AF3EE57B6DD5FB87564DE3F187150FC,SHA256=ACC5625A2C7695C41F90F45C29ECF33FD3181D03C8FF87F12CA3424CA6C8A797,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044377Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:16.005{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5156FF54E0324C407062A51593D9ED1,SHA256=0B739A7AB9397B6CC4FECBC1F069D0E70CA9D827A013682819958FE96CFEDA4F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025493Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:17.970{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9A453D991CFDF36E69254AE657BE80D,SHA256=4388DEE9FEB333E8707E33A95A05FC3E7F9792E25730201F2A07D215C6A54106,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044379Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:15.745{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51630-false10.0.1.12-8000- 23542300x800000000000000044378Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:17.035{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=241394A0E426901CAC6996F7F5731CAC,SHA256=130CFFB5831417F7C0A1D624EDA5ADCD67C261DA58FB9BC24A9E565F739CF24E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025494Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:18.980{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B23771DDB657F135C490BA26D8ADB446,SHA256=2DC7BCC83755056EF246CB43B7A9FB99B40790178D33B1A34937DFC2EBBE291B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044380Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:18.053{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9216A6D49FF0EAD6B9EB223D42D2B943,SHA256=BA4FA49E99F96A2154311354D416BD65B2736E1DD2EE6D6F4E1B9E329F40F863,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025495Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:19.996{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CE62C3D669EF5F9163DC72DD3DC87799,SHA256=35D7A6CDF35E13C6D5923C9EC30856FE600D876705D98D27AC424337E6080576,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044381Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:19.071{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F39FCB1A2727E09A3F93419996EB315,SHA256=C19BA712639E4865E9212A99D331BF89C82A7CB224E3460797313318A4194CD5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025497Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:20.996{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1AAD5BC6B548BAB119B9A3FB4897ED1D,SHA256=0FA8BD04990254B25C858E1365B55DA6E637E910800E39177BA4ED7E8F1EDDBB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044382Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:20.102{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03B18FCFAED2182AAA6AE514A2FA70C3,SHA256=BAAC7C7B703B2D531D4B87609431ED2D5CEBC5388202A26FAF061D5AFA247144,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025496Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:17.912{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50887-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044383Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:21.117{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E469CDA2FAA2183A4A191ED41D65E729,SHA256=5EFBD1B49FCC844949BFCCAF5F49EDDCA6244EE526E7DDFCF889F5B87116CDF1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025498Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:22.011{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0AB08984C59DC29CEF3C8E0B9D0B2CF9,SHA256=EC35A4FA1B76AB81918A6F0DAAF669FC74FA3FFA53FF71C21FA27F801E66E0A8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044384Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:22.132{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E225EAFCA33787792EA8641D24442BB,SHA256=3D9C1C6035107E1CD2D8F1916DB0024900D06F13E30B85F61E4DED33B05F9164,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044385Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:23.169{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D6799B7BB0D39047F5C534708AA6EA0,SHA256=F846F7335BC49B6D966F27B9492C6214869774C3544D91D5AE2D5BE9E0D323AE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025499Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:23.011{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C69DE48CFF5E3AA112650E0D5E75257F,SHA256=5D0800A7F77F547F00A2D5D36DD884A1844E5D2B0D56EBDB25C0430F7AF8B030,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044387Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:24.199{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2D2E2FD0E2D5B1E76AE88628C18A0B8A,SHA256=6DBB0550607683469ABE050C4C091922253301D2E45F5C77381F1FA99EB35B75,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025500Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:24.027{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1927E89632F79BBAEA2CA46DBE431580,SHA256=DECBB2587741E08742858F1A8253CE1A83BED4AA53C6F73F7F9F1D023B39525C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044386Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:21.641{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51631-false10.0.1.12-8000- 23542300x800000000000000044389Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:25.633{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-099MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044388Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:25.200{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7E4BA08A09DE806AEA313C63EC93F827,SHA256=229CAE4F9A3EDDA90775ED02B8C71A56B7F84B87312186B0D3BADDABC1287E8D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025502Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:23.873{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50888-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025501Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:25.042{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BAA2D3C61AEF41210C82035B4E17870,SHA256=8D7886EA60CC22E242BB2E59E8564E5908A303FC503E4FD9C767EE5C979FFD16,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044391Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:26.647{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-100MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044390Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:26.230{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37B6D67DC1249E6B5BA8290B9E938438,SHA256=1542E3F570B2F55AB9956970C4D6A49E77C19DA43DDAAAAA9D096EE07BD38BB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025503Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:26.058{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5D34FAF3471AEEC6C744BD604F4EFCF,SHA256=E0622813F5C25953B4B46ABB283E74BECC0A74C48A28A0C358685A404C9BE2FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044392Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:27.232{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8FB6E1624CC6B12E47993F4578521BB,SHA256=846CEE5D6075995437D8940276A2060B7A34C5587418EEA4A66A2DE4ABB83084,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025504Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:27.074{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E13076A53DC087668538FE3FB704AE4D,SHA256=E22D520671B42A3B2CB4AE7B7EE10221C12F97167553B7131FBA8B0A2215289F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044393Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:28.267{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B63E461E126C509367552EF6914A036,SHA256=D37A4D722970ACF12D34B2A2147605F5D8EFA874A773D0BAC60B7686950CFEF7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025505Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:28.089{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3227C8B72AA67F962CE86AAFB8090825,SHA256=EC2BA23096BAE29992BF01B96D063601674004824F9819357FB81F4490FBBDE1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044395Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:26.861{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51632-false10.0.1.12-8000- 23542300x800000000000000044394Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:29.282{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5A0BC1C974E06BD6479D8896950AC0B,SHA256=B92DD9B8A969D8B3CE98626F72D1F09C152624923859E5B1CBED2552DDEA4806,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025506Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:29.105{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA871C2FEE9A20E7D6A6D3C45DDCBFD9,SHA256=F42BD85E724105DC6639D9E3377A86D388A4AE5E96C27D54A4ADBFC10E96B573,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044397Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:30.297{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F58A084675511FAECAB3E07E53DC137,SHA256=F8E3DF504939220B60BB5ADBE2181B051FD49DE9090359BD27EED029D880C8B5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025508Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:29.076{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50889-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025507Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:30.183{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BA26E9D26FDAAFA6675B4C4653C5A45,SHA256=57FE99272BB816DA6DA515D5AC983DD6EF47A42B75F6EDD78F4BAEA2B5705A4F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044396Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:30.197{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044398Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:31.297{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8865218FC2D966C1A67E03F8178811DA,SHA256=B42809D6DD9A9E27A0DC5048ADAAE1153E5ABD881D4C706BD1452CD454BA62B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025509Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:31.230{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=217CF14CBB22DEE3D85619ECEB676D49,SHA256=72E966AA3D340AF4E27F0DC3B5139045FFD68F5D67ABD49CEC82C37158021427,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044400Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:29.775{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51633-false10.0.1.12-8089- 23542300x800000000000000044399Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:32.328{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41EA1AB361496C553A165804D77EE9A8,SHA256=3A866ABC01191422D2BE6904732F9D6CD8646EB8E18A6954F1F1968BC5EC95B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025510Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:32.230{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C030CD6803DA0BC8238EE7268928227,SHA256=1639FE86497C0E374EB8DA22DE5649B072C629DFAA59118C5A150FBC950BD744,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025511Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:33.277{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6E3B62F35CEB49DC77CCEAB6FBD0D7B8,SHA256=985D4A92C35D6EAD5E7C8710992BD7EB4EA6F85B713EB677DC60ADCE7F64E70C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044401Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:33.346{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B27340EB61E1C1947111987EB0D5AEF8,SHA256=151BFE7BAFDFF6360F15CCA83515B1E82591BD8DDF5EFD69F5DF4E1A00CD0B81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025512Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:34.292{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3DF6A66AF8A05C2D5779F46FFA87473E,SHA256=F22AEE9204E68B2E23EDE2BC8BA889C74C9F9CA82FCB1C68992F5E0B835D9926,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000044413Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x800000000000000044412Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x005e5f7c) 13241300x800000000000000044411Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7a31c-0x62564396) 13241300x800000000000000044410Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7a324-0xc41aab96) 13241300x800000000000000044409Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7a32d-0x25df1396) 13241300x800000000000000044408Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x800000000000000044407Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x005e5f7c) 13241300x800000000000000044406Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7a31c-0x62564396) 13241300x800000000000000044405Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7a324-0xc41aab96) 13241300x800000000000000044404Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:40:34.510{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7a32d-0x25df1396) 23542300x800000000000000044403Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:34.364{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44C54E660251847AE5A1844DA5ABA1D7,SHA256=D65C02A9784880DCA57CF450F42575F9F1FE54CF94E71B179E2E959D5E53ADCA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044402Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:32.658{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51634-false10.0.1.12-8000- 354300x800000000000000025514Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:34.108{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50890-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025513Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:35.339{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=57067BC13AB340D9A8EFF33C40F968BB,SHA256=B98449CC0193913C1B48C5C9395CB621C7540C87CB06AFC77870D88DBB539B48,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044414Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:35.395{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=267C40CE04C9324B948D65CAC2E7C762,SHA256=84FE28DDAE2ACE3DBE2DB25E3240DBEC21187D7EC5FB9F6DF1A5C7FB928EBB7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044416Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:36.426{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A764167A9DCDB001F9985A7F037D77C,SHA256=70DBE05499564B1A71BB221C2B51E4583D386F64FFCFD10E88FA166997C6FF6B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025515Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:36.355{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8D95CF5B4CF5EBF4CBA14AAE2A5840B,SHA256=932A6C8CBA9D1BCEB11B36ABA0AE798E3B71EE50AA205C63716FEE5326FDBC16,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044415Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:36.210{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=0C6590BB0FDD6A0EBD22FE04D12F8650,SHA256=185CBA4BC7F6E100926D66D6247091D34EA430CADFB0D456E49EDA1F55BD19BE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044419Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:37.444{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F0B3466A41EB8CB93D941F36B24876AB,SHA256=74F035936C461C22DEF14CD84A49018CD15199EC9495EC1983EB7DF11F958BB5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025516Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:37.402{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8CF096269B5F274EB1D87F07032E2671,SHA256=45ED1DF921B5800AAA6E2A63E11FACBAEAB77868B106A178DB2918463F7EB317,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044418Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:37.210{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=EE176543C44EB978E885EB77DAFCB769,SHA256=6EBBA66AD6A7EEC95216D6C43A3ECFEC7B50346D4BECEB614F010FAFA2EA575A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044417Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:37.210{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=1182936DAC3C905632D409545A6CE5AF,SHA256=B10E4A104824FC69A4EA61D2027809D6AF65731D32E2733470718A823329C1F7,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044421Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.862{323FE7D8-022C-6136-0B00-00000000F001}624812C:\Windows\system32\lsass.exe{323FE7D8-022A-6136-0100-00000000F001}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96ef2|C:\Windows\system32\kerberos.DLL+793e4|C:\Windows\system32\kerberos.DLL+1443f|C:\Windows\system32\lsasrv.dll+2d211|C:\Windows\system32\lsasrv.dll+2b3d4|C:\Windows\system32\lsasrv.dll+30929|C:\Windows\system32\lsasrv.dll+2e287|C:\Windows\system32\lsasrv.dll+2d211|C:\Windows\system32\lsasrv.dll+15ded|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 23542300x800000000000000044420Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.462{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=63936DF9C5BF7C972B5F77C90CFDAE47,SHA256=831023150D12D468D0CA62E851F4A9626F8D7ED37B66CF719858DCE5BB428002,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025517Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:38.449{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC5926E3384773DB32E98BFD47FB523E,SHA256=EBA2810E494B181829EE68FB6F4AEA3B8211C2366C64C95A4A563D6709B0A2FB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044424Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:39.761{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9BD1D7A1EEAA6F7725D70922CCF1BFE1,SHA256=FB2ED659FDF8430EF83E1334F1CCD5B78932EDE45A9E06AB26FCC9EEAC456F5C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044423Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:39.761{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BE533C492EAF7085F9FF0494FB1D0E3E,SHA256=EC1E0FBE264031485D011FBACBA66BD3F2EF08F0ED85BF38EC1675AE56F05CAF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044422Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:39.477{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A4D822BE77E756721F3A50D6D32F669C,SHA256=B73686E15C203FB50F8ECC3DB1ECBDCEA6D618A32ECE014188E353E4E369C22E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025518Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:39.453{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=230836006AD7E9EB5A30C98DA2980C05,SHA256=84E40BDECD13624DA6267D0509F77B6113860F5F37618D3D5A07529989C77712,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044432Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:40.507{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E04A66DAA095C78B6A8E59A515612FB9,SHA256=0B39054364C365D32060A1A5563C64F1A0F4978CBDA6E3DB1E15D837BAF2DF11,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025519Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:40.484{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=91FBAAD05D7707E35A65FA28A7D8EFBB,SHA256=4ACD8CA1A2E4EB04EEDD891284C899B3A7BEFB752121ADB458770D28875DBDD4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044431Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.459{323FE7D8-022A-6136-0100-00000000F001}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51638-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local445microsoft-ds 354300x800000000000000044430Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.459{323FE7D8-022A-6136-0100-00000000F001}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51638-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local445microsoft-ds 354300x800000000000000044429Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.345{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-456.attackrange.local51637-false10.0.1.14win-dc-456.attackrange.local389ldap 354300x800000000000000044428Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.345{323FE7D8-022F-6136-1600-00000000F001}1308C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51637-false10.0.1.14win-dc-456.attackrange.local389ldap 354300x800000000000000044427Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.336{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51636-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044426Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:38.336{323FE7D8-022F-6136-1600-00000000F001}1308C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51636-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044425Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:37.787{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51635-false10.0.1.12-8000- 354300x800000000000000025521Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:40.065{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50891-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025520Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:41.484{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B97B13AE2B62AEB30FA77DF604D993C,SHA256=05C51DDD57DC4A905128C2F208BF7E049F4F4C153739269EFDB1879E39ECD67C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044433Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:41.508{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FF34EB21281D0C180B177E45042C189D,SHA256=B8369F3A03DF19F01187DBF0868F3A560C5D846D4A911EA10809665135E3CDCF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025522Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:42.500{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D94E866B065A8ED241C9E36D69DA5207,SHA256=5BE5093AB755432E220B94A410C3CA96B6F3AFBC6DD4E5C1D6BF291B8ABF94FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044434Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:42.522{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=158535C7494CC8D1823BCF7BAD853F72,SHA256=26F29103CDD62AC905848D68494D01828C119D545B3B4673C7DCCEE84FFB72DC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025523Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:43.515{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=69FB3293B6AC2EA92844D49E60A09166,SHA256=121B491765B916A722DED5C054241763C81282542212CD7D2963174D2E88DF78,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044435Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:43.540{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=43940C75C9DCEA56573A4251622619B5,SHA256=73B01B577881F1FE375D5A285E1BC66304C7CADAFC2A0E29C5E592571400ABEC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025524Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:44.562{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08A4460F64A7AD4F4157B529F76ED9AC,SHA256=BAC82E10614A55B63B7CD6771C95E449D1276EFCD067AD4DBD496FC6B6679D90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044436Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:44.574{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ABBE668E5EB7CA38D2A4D7D68C36CC57,SHA256=892CB546FDD4648D7290BC140BB7537A46C2728C3F449D2499BE377BD5B48AE3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044437Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:45.605{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A65E9340AB3867AA335FD374EBEF3AC9,SHA256=D43FF31897E7F31B21AF9F2376CDD5EDE1233067C750F48348183986C08A0A5C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025525Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:45.562{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=69344EA360CD6C91BF717230209B3C1A,SHA256=5AD8FC9B61325EDC7D6BC08E9BA527ADB46019657A811D35EDBB45F17DE013E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025526Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:46.578{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A84E9D8D146EBD602A90C3373357A34,SHA256=24F9CBB3B79AA0746C87CB848C4C13451D7CBAC74CD048F16B547A0E737204FD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044439Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:43.668{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51639-false10.0.1.12-8000- 23542300x800000000000000044438Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:46.638{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8623E8F215C3106A0A9A8A8A690435ED,SHA256=01C94C2E1A727E38F84CB4BF629F8516CFBFB1DF8E9026F861F7790B12DAAC7E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025528Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:45.909{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50892-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025527Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:47.578{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A827078615AD7C13680DFB71B017A9B0,SHA256=4445994F11F584669CC403D7885641D8DB77ABF3B37A896D44317FF3609AE99A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044440Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:47.656{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=013C19EFF39E4E8C87D72BF15776CB3E,SHA256=F74DB41A10F155B82FEDC300C2D1527BA780FA22C1304750B4E67A3D6E4FC38D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025529Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:48.593{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=422F2D065FF2C35A99AD5E7E3DF84FFE,SHA256=9029CB95537F990653EFF63C86EDDF3FCA52B1F13B33051DAB5A80448B48C8D7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044441Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:48.671{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC62D8331BD5C9BBB4896ED144C53BA1,SHA256=C0FA349CD08B1AA0E7F7352183A62AB247A721B012D4A67E5DAF2723B0846A9C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044442Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:49.686{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD334901EE5462534D31B7F1A6485532,SHA256=44CC1C334109603D5983A1EC515401DAEFB21B9274C7261C24A8CCA99CF755C1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025530Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:49.625{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD90640CBB9D1C5A5BCE9564DD9E930D,SHA256=88B9F61858D4DFAF80CD7FB97614C7E44F825FF46BDADC5C64A5E5F0248C6CC3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044445Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:50.701{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=423A97F6E7FC0D33ED8E65F835D42282,SHA256=8010B5C20B61078BD0C5A9D2AF35204066A149BCEC9D390457FC8B399A9D2641,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025531Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:50.640{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5D7035DCDCCFF185A7F74A9A541077B,SHA256=F177105E064AAA7A534EDDA50D71F3A56B51B12E126EB066921D32EAC7E97C0C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044444Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:50.617{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DFAA33B0B8DB071F1C7E93CE96BFF94D,SHA256=5E0FAD2A0B1BB877D1FAC71CEBECCEEC2C2744DA06DEA2A4E59E4C2F997D85E2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044443Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:50.617{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9BD1D7A1EEAA6F7725D70922CCF1BFE1,SHA256=FB2ED659FDF8430EF83E1334F1CCD5B78932EDE45A9E06AB26FCC9EEAC456F5C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025533Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:51.656{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BFCEC477A1F0F58463352A76D97600A,SHA256=1E5BA529F41278A8BE5741196E49D886E5C7B69E07E87444C5792A8C937A408C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044446Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:51.716{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4346A2FBE684CE204D8FA2814A61FE65,SHA256=2CFBBD9D803D134DD001277C551C6642796E83665E183E3C37C0CCDE1C80271E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025532Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:51.593{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=94DB929A91006AD8F9BC17BD612ACE28,SHA256=374E1164B3EB7BBCE75066A68BB5C6798DFB5611864F3600FC9743D6973D6E58,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025534Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:52.656{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37DD9E862F233F9F209215C9CA18DD8D,SHA256=24F3CB51903A890F524B3C3D0E61E27BE865370F2AF942F160102BFD98AD34D7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044448Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:49.663{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51640-false10.0.1.12-8000- 23542300x800000000000000044447Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:52.753{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3FFB8DA49062C873AB55D8CFBAA8042A,SHA256=54609E1CCC97AF7A574ECC977C5C53E7CB0F56F15050E488686A14133A9FAB03,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044449Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:53.768{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=74E38C91794F7B69FAF716DD927452D5,SHA256=6E7A8AAE58C24203C99F4C5EE69EE5EB02E9C6BD639ED6AED5C09F5EE4383682,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025536Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:53.672{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA857D62F41E7CD4E4CE4D4BE6458FF2,SHA256=4D7A011D6A8FDF9BAD1A5EF54C8A41A6BC3A0C5E226E10ABDFC22E7460F80F3C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025535Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:50.940{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50893-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044450Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:54.774{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=952A9E4D9847AE034D006800F0FFD208,SHA256=00FA3E0C94A900D6B7F0192D8CD82B12BD3C4D35B45F01F31B6D3DC9C8FA9D66,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025537Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:54.672{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=446E0A4EF1AB8CA0C3E45695FC10FC64,SHA256=1B3D6396C58996DD127327F3BBF02A6612DB39267DD93ED8A0D3B2105E85EA24,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044451Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:55.789{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9311A83CB4C2D29F0367AAE74DAC4D51,SHA256=A33E316C5DEC1E19EBEEBBC7809864A12141F05689B1798901AA76B70D4BF542,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025538Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:55.672{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97C8CCF7C600FD7B93172931159110C7,SHA256=B60AEA440AFD153312FDD79C95B1CF9EA78550A0BE4FBC82ABF1282998F923CA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025543Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:54.888{FFF7FB96-0422-6136-3A00-00000000F101}3056C:\Program Files\Amazon\SSM\ssm-agent-worker.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50897-false169.254.169.254instance-data.eu-central-1.compute.internal80http 354300x800000000000000025542Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:54.794{FFF7FB96-0422-6136-3A00-00000000F101}3056C:\Program Files\Amazon\SSM\ssm-agent-worker.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50896-false169.254.169.254instance-data.eu-central-1.compute.internal80http 354300x800000000000000025541Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:54.754{FFF7FB96-0422-6136-3A00-00000000F101}3056C:\Program Files\Amazon\SSM\ssm-agent-worker.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50895-false169.254.169.254instance-data.eu-central-1.compute.internal80http 354300x800000000000000025540Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:54.754{FFF7FB96-0422-6136-3A00-00000000F101}3056C:\Program Files\Amazon\SSM\ssm-agent-worker.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50894-false169.254.169.254instance-data.eu-central-1.compute.internal80http 23542300x800000000000000025539Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:56.688{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2499D45089F0F71930E043F7DC8EDE7B,SHA256=3EE08EEEB3084A7809ADBD678E069131C1AF0D60C42B259E71FD2C17F087A9B3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044453Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:54.714{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51641-false10.0.1.12-8000- 23542300x800000000000000044452Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:56.804{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=31246043005E2392F6FCF7B4948AACB1,SHA256=B9D649D890B500B3E7DEF5E368B1A87C3CC22056C5C968C4C58927F6D910FDD0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044454Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:57.857{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=89FEE6F78F1BDAEEB48339835690A5D9,SHA256=FD2FC270DB14667B877B55452DF4417EE7A532DBD29E2284BE4337DE79B1CA8C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025544Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:57.688{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DBBF54EFEFDBFAE15004D8CD69DD78E5,SHA256=A6F536D4C97F5F5DBFAD4DBA2D46272CD343D2CB05F8C1F9A67D5AAE82EB3892,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044455Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:58.872{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7699D876C3B357DD89C2AD01FA5A427A,SHA256=E65FF3C4E586D71515E96C83EA5F3978C4F4095EEE500CD4C047E6CCB3AC03F8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025545Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:58.688{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50484290E57EC7E4136A94D29D9AF1AB,SHA256=DF1B674A8C06B3BDC0A2D0F09094E60945E36D0C7F2CB8257A655617DF30D61A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044456Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:59.887{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=059587BB3576FEA1EC6841CD57F6174F,SHA256=00D74D37B6A9A810166EC2AB0736F6D7D7AF2EC08A19CC0DB9698D8B59814A14,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025546Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:59.708{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FA70783977E57DC16947B9884C40F7D,SHA256=5C2BB8F087BAA4D7D8D80D0415CFC96AB0F81C023F0A1F10883384B5DD1F0FFE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044457Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:00.917{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF39AD40EBA744A52597289C491F6410,SHA256=5FB8B32FABD249A26167F06DC85387059AF9C24DEBCE6011E12F6BE23D95FAC3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025548Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:00.754{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C20FA6E4542A924C65771B7EA9620D3,SHA256=4091B23CA3959999D37997A40CEBA7C46BA27FFEC7ED62E177B9E1DB19CE3599,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025547Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:40:56.894{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50898-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025549Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:01.786{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3179C27940B8812DCBFE5514C58DFF9,SHA256=7ACE87C7201DBD3D33EBD420972A56344024FD3E48E4807C2F630DC54EED9465,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044458Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:01.918{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A3F1C36389128157F8F3FA47E76510C,SHA256=7E92F4909D1F5596BAAAAA1F9CE92C57985A1112775B37692357C4AD964B7F5D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044459Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:02.927{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C26F15C0E0105774F72C39F9A3F9EA8,SHA256=BC41B28CB40366A16A33DCBAF037D226425E519767493E5732623275DF1970F0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025550Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:02.786{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A0F6F970B82E0338C70EB8FF6876203,SHA256=F8B965820B5F9042A703CC30B2DB772AE871964C03E84D7DDD4E8196E063DC8A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044461Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:03.945{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC7E1757141CEDBEC5543B8627F3E8D1,SHA256=3EB26C561332D4E8C8C52A7C45E21BDE755B0E1EA14670E2A452B7E1C38C3A8B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025551Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:03.801{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD93D908D6E9A907D3A2960B1D81EB57,SHA256=34FD33139DC444A7C722F5426D404216BAD555247D7D63E833FB44DED309EF8B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044460Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:40:59.826{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51642-false10.0.1.12-8000- 23542300x800000000000000025552Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:04.833{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15CCCCFD3BD3DAD991755EE6F0BFA943,SHA256=DB1F442808C23034B8A82B98D1A9A3460D7FCFD9BF6DE77A2E704D35FE1EEF2C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044470Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.963{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D17F1D9A04F660D7B1305C89A0343A2D,SHA256=A7831DE93BFAD275795AD7F28AEC9040D7CB423F559262596B99353B42B767C2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044469Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.446{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A70-6136-D808-00000000F001}4532C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044468Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.444{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044467Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.444{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044466Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.444{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044465Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.444{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044464Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.444{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1A70-6136-D808-00000000F001}4532C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044463Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.443{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A70-6136-D808-00000000F001}4532C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044462Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:04.442{323FE7D8-1A70-6136-D808-00000000F001}4532C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025581Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.895{FFF7FB96-1A71-6136-5206-00000000F101}2864432C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044490Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.978{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A60BDD1D9503398C66E5368C442F53B7,SHA256=E85BA6A633F7CA06622BF7FCB93ED7EB2AC1BB302297B3B1F2E91B68910A6F6E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025580Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A71-6136-5206-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025579Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025578Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025577Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025576Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025575Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025574Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025573Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025572Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025571Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025570Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A71-6136-5206-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025569Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A71-6136-5206-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025568Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.708{FFF7FB96-1A71-6136-5206-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025567Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.692{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025566Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:01.992{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50899-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000025565Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A71-6136-5106-00000000F101}3548C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025564Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025563Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025562Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025561Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025560Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025559Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025558Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025557Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025556Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025555Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1A71-6136-5106-00000000F101}3548C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025554Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.036{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A71-6136-5106-00000000F101}3548C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025553Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.037{FFF7FB96-1A71-6136-5106-00000000F101}3548C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044489Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.962{323FE7D8-1A71-6136-DA08-00000000F001}64246124C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044488Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A71-6136-DA08-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044487Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044486Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044485Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044484Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044483Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1A71-6136-DA08-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044482Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.794{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A71-6136-DA08-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044481Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.795{323FE7D8-1A71-6136-DA08-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044480Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.462{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4ED1F811DAC1ED687846C4B1BCFF94E5,SHA256=7676B066993F69C1E01D6AA44406573A209CCA24678E634B88F4054D9FE5BD45,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044479Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.462{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DFAA33B0B8DB071F1C7E93CE96BFF94D,SHA256=5E0FAD2A0B1BB877D1FAC71CEBECCEEC2C2744DA06DEA2A4E59E4C2F997D85E2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044478Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A71-6136-D908-00000000F001}4984C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044477Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044476Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044475Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044474Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044473Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1A71-6136-D908-00000000F001}4984C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044472Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.125{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A71-6136-D908-00000000F001}4984C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044471Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.126{323FE7D8-1A71-6136-D908-00000000F001}4984C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044492Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:06.993{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=922D1283AF5224A21B5C067CA57898A2,SHA256=C0A66654D2916B21C867D8C4C8AAD0960539BB87E225C6364B7798670AC7D1F9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025598Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.926{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=579B55F9AE31E7571085F1B76860A6DF,SHA256=FCEDF25C19B1517CFE97B3D8A9937AA168A5C15F94398D62C85AA4842A5B1651,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025597Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A72-6136-5306-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025596Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025595Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025594Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025593Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025592Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025591Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025590Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025589Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025588Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025587Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A72-6136-5306-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025586Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A72-6136-5306-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025585Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.380{FFF7FB96-1A72-6136-5306-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025584Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=697812627D0E47C729DEEE89A2593A79,SHA256=6246B8C07370A92F74CAC2145BA51E652A4C5AA15C7439E3C800005388BCFFA6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025583Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5BDFA0F7F53176DFDB668BF4948C75E6,SHA256=00E1F56D560CE215CD44D1DBA24799201BD5650775734C598DFFA5E20C4299F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025582Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:06.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A53D19F6A968D68264140931D64D41DA,SHA256=2C98541E75C038021CB25820A9D7E497C614C807A697EF56DA67053967091398,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044491Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:06.593{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4ED1F811DAC1ED687846C4B1BCFF94E5,SHA256=7676B066993F69C1E01D6AA44406573A209CCA24678E634B88F4054D9FE5BD45,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025615Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.942{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E313FACA9BCD7B01F36BC092287712E7,SHA256=88E0D7A127E5E1CDDC387D547D9ECA61CA7DE16762DC0842736D76BD3B694F61,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044500Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A73-6136-DB08-00000000F001}1048C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044499Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044498Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044497Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044496Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044495Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1A73-6136-DB08-00000000F001}1048C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044494Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.977{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A73-6136-DB08-00000000F001}1048C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044493Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:07.978{323FE7D8-1A73-6136-DB08-00000000F001}1048C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025614Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.583{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=697812627D0E47C729DEEE89A2593A79,SHA256=6246B8C07370A92F74CAC2145BA51E652A4C5AA15C7439E3C800005388BCFFA6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025613Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:05.523{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50900-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 10341000x800000000000000025612Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.473{FFF7FB96-1A73-6136-5406-00000000F101}40082980C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025611Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A73-6136-5406-00000000F101}4008C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025610Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025609Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025608Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025607Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025606Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025605Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025604Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025603Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025602Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025601Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1A73-6136-5406-00000000F101}4008C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025600Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.333{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A73-6136-5406-00000000F101}4008C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025599Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.335{FFF7FB96-1A73-6136-5406-00000000F101}4008C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044515Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.979{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A596F282BE42007966C6B8BB3064B3BD,SHA256=D7A9BA2DA5DB7F861CBE9603FB8AE2AB48A2D33ED9BA962849CF53A93B89A306,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044514Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.849{323FE7D8-1A74-6136-DC08-00000000F001}1176844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044513Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A74-6136-DC08-00000000F001}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044512Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044511Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044510Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044509Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044508Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1A74-6136-DC08-00000000F001}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044507Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A74-6136-DC08-00000000F001}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044506Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.661{323FE7D8-1A74-6136-DC08-00000000F001}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000044505Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.819{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51644-false10.0.1.12-8000- 354300x800000000000000044504Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.171{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51643-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000044503Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:05.171{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51643-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 10341000x800000000000000044502Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.177{323FE7D8-1A73-6136-DB08-00000000F001}10481688C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044501Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:08.024{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=49852A91E1C8B9250C89B0ECA8D7CB1C,SHA256=9B3D06280E296A1B8F1D0ECF58879D543488E5B632EC0390737D22ADDA6F3183,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025644Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.897{FFF7FB96-1A74-6136-5606-00000000F101}1308928C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025643Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A74-6136-5606-00000000F101}1308C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025642Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025641Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1A74-6136-5606-00000000F101}1308C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025640Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025639Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025638Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025637Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025636Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025635Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025634Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025633Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025632Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.676{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A74-6136-5606-00000000F101}1308C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025631Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.677{FFF7FB96-1A74-6136-5606-00000000F101}1308C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000025630Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:07.070{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50901-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000025629Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.161{FFF7FB96-1A74-6136-5506-00000000F101}1132912C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025628Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A74-6136-5506-00000000F101}1132C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025627Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025626Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025625Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025624Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025623Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025622Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025621Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025620Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025619Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025618Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A74-6136-5506-00000000F101}1132C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025617Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.004{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A74-6136-5506-00000000F101}1132C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025616Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:08.005{FFF7FB96-1A74-6136-5506-00000000F101}1132C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044533Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A75-6136-DE08-00000000F001}3336C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044532Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044531Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044530Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044529Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044528Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1A75-6136-DE08-00000000F001}3336C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044527Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.963{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A75-6136-DE08-00000000F001}3336C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044526Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.964{323FE7D8-1A75-6136-DE08-00000000F001}3336C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044525Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.447{323FE7D8-1A75-6136-DD08-00000000F001}61281780C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044524Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1A75-6136-DD08-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044523Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044522Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044521Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044520Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044519Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1A75-6136-DD08-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044518Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.279{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1A75-6136-DD08-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044517Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.280{323FE7D8-1A75-6136-DD08-00000000F001}6128C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044516Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:09.026{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B48DDBDD213F9D6B86CA80364071095B,SHA256=D6C833F175DD548699DC2AD872C6CED0BC19719C4D6B8C56719FD7F428057D3C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025659Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.192{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2CFE4DC9017D78E6C1018FC1D5C03611,SHA256=4D3E696F877DF15A58523231B0A3CA1464FDC9A67ACA6BD0ACF25A778424F1DB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025658Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.192{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E286306C9B0E61BED40915F3230AA7D4,SHA256=14AB72ADF522E0426DFE35DB3ABDAF9D42183E047DA5487252445F183F364F2C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025657Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1A75-6136-5706-00000000F101}832C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025656Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025655Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025654Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025653Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025652Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025651Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025650Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025649Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025648Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025647Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1A75-6136-5706-00000000F101}832C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025646Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.176{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1A75-6136-5706-00000000F101}832C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025645Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:09.177{FFF7FB96-1A75-6136-5706-00000000F101}832C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025661Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:10.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97F3A4CD910872A4256F9A89F63F050E,SHA256=A853CC4B90DB37EB6E9472ECB80F378221512004557AC7D3597897B167BF54A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025660Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:10.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A53EAF56E4345CF96B1B6198AE4E0BCB,SHA256=3C48710094C1CA61DAB54ABA059E14474600CE72A22EFF60743DBF3E9B7726D7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044535Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:10.284{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=53AF0CA5DDA216581CF60B383F4CCB66,SHA256=CBEEEA87ABA3CF5D231FF2F01F8DE5AEE70DCEF01F4F2C81E49BA07DB8305268,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044534Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:10.053{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0D3FA9EC8082FD19B5C0A78FC51D88F,SHA256=096516898E8245F50BAE07053F65BB3CE6219836B956627CCD3238E2E7ED2147,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025662Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:11.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8CF0211D1AD44AC024D9C6E0E11E6326,SHA256=BC6CD68C23BABD4BEF2CF9066B4A403CE33D68D08EFAC57F6A052312EF2D56BB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044536Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:11.068{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=245501849D210A0DB23DDD3CAFE4F36B,SHA256=FF465F59D965C2CA69DBE825DE3146FCDEA34725422053A0A908F9A771DE53CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025663Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:12.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B4954CAFDFFBB763E1F9536E96D242C,SHA256=EF864424D9B6EB2CB276BD1EF524A39339457423066A47B0BD8AF9AAEF01B405,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044574Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044573Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044572Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044571Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044570Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044569Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044568Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044567Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044566Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044565Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044564Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044563Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044562Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044561Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044560Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044559Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044558Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044557Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044556Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044555Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044554Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044553Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044552Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044551Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044550Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044549Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044548Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044547Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044546Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044545Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044544Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044543Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044542Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044541Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044540Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044539Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044538Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.298{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044537Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:12.083{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB65915A558BDD121D83E09A06A2CC17,SHA256=9FB5BE11563300DF8EE750A7544B882196206B0611713F65FE59829BB12C0FAC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025664Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:13.223{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4BA3F8D4EEAC69C3C239416DF6BD0599,SHA256=A0BF4447EBBAE52CE5117223E462886C04FA82A32B96E21AC9E521FEFF9D436D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044576Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:13.229{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7272AA64E800EFD1D833CB060C08FE4F,SHA256=AA75A922F5BCE5408B91533DA6B7EAC11ED2F0B622F7E58AFA7FF7B95A24E5C3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044575Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:11.660{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51645-false10.0.1.12-8000- 354300x800000000000000025666Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:12.913{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50902-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025665Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:14.239{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F39578163F5A5F90E6D7042E3490B343,SHA256=B52C8BD715EAF1A4DAA2C198BED1C216F77DC1E1FA84761DF6DB2FB2E308CA7B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044577Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:14.150{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F21BEC487A45CE4E4263EE454DD9C626,SHA256=B7FDE824FCE3BD9DEF8ACBBCCA4BEC0E12C242FE10AB1A83F2B0DFB0595256B3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025668Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:15.491{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-092MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025667Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:15.239{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA32DB972ABDB9A11A787309F31D7FC2,SHA256=45ADEB603E255ADF4B88C1EC6CEF18D9655E254CBD6D00A475646BEC54290506,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044578Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:15.165{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11D71A375B79AC7C2C00F32EACC3B4B7,SHA256=FDB9AC535A8B0DB9A5ED363C1EBDD2D7ED238109DF8881E8C6584D75B307BB82,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025670Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:16.504{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-093MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025669Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:16.253{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FD9B1507FEA4295CF4154C05A893B36,SHA256=88D23B8F1070FAB66326B3DCCDF565A09431367511B876C0A23EB9682DAD89FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044579Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:16.195{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9BE688ECF1D5779043690BD533D53A8C,SHA256=D06F0F161FF7DEA76A0664B21740E22E5A318D46A72F00C98FE57DD650C95F1E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025671Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:17.286{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=809EC2BEAF019BE1C8C4BAB5B1452F3F,SHA256=D3BA602761C8FB1B685EF8E75B01D8966A107851F61C299130E037B46ED90052,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044580Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:17.211{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=556C8704CF16EACF4D868CB404B0FF58,SHA256=A20E7E26A77F5CE75558C9DFF9042E93D43AC447B6455F51ACB221763C1927B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025672Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:18.317{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3C242B0720D52987F495D3B535121455,SHA256=BF0A355EB6F7A853664B83101BA7057184EC91A64CD9B68F7FB02F2097553962,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044581Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:18.226{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2BC29B68831B0CF860611658F7CD0634,SHA256=CAEC2998E8BD416397410F570BA4F3522D49EBA303758E0A1E327F2137067FBC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025673Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:19.344{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D35C4952A72080A3A2FAEADB74D8108,SHA256=EAACBD597A9134DEB6F51FF4056B389C9506BA4E22613FB63400E6A00E21AB5B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044583Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:16.719{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51646-false10.0.1.12-8000- 23542300x800000000000000044582Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:19.263{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3122D56D37FF2807AC728D85C60F026,SHA256=ADFA109C45A572D4DBBB6000FF5B2DA8C08560C0E8B7F9565A8CAD7578C47755,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025675Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:18.909{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50903-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025674Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:20.359{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F67236880F60FEB848F7D7D25038AE39,SHA256=FE4525AE0903162559BE251C789902BADCCC8733BDC3E127FD0EF66DED0FE121,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044584Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:20.278{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8297190046309C0BDB58EE25ADB61112,SHA256=433A268FB1C59C2E43222BD48BE46FBE99C5A1EDFDE874357671E531326666C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044585Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:21.293{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=28CC4C39E6350B96176F8355A6594F89,SHA256=0658E381E23F9EB93A3FD8C57AF94EB788CBD3F4AD18FEE2A2A285E5B2F6E33C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025676Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:21.391{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32218DAA1830A315B7878903635637EA,SHA256=B8C7DCBDA9E11D37BD4A0C57014ABB539A17788EF710C15C8ADDE776C19EE8B7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025677Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:22.391{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF98AB79876CFC429B51D40EED2A6CCF,SHA256=27F12A4B6F6A2C3762D97A9F070CB7C9B0F448676F687D85A7A02DF579380E5B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044586Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:22.307{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=738C6D46763DD64B444E373FE62A5458,SHA256=0686277F541BED1FE1171CE2CB9E3E6AEA97325A5298CBD315CD8DF1C8522224,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025678Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:23.391{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC0EB5C453AF4463899302F77B3641E7,SHA256=C3BE00369BB2AE708461F1076B4A294411C2B79B410E6269F8EDFE72965C617C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044588Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:21.753{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51647-false10.0.1.12-8000- 23542300x800000000000000044587Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:23.341{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=474061E2174EA6C29E8FBDF658E69B08,SHA256=9499DCE2377C550A4B8B0C5CB2469045C31CECAC812C6CBD6B5DE196F843F775,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025679Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:24.437{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A700BB1DB46578AC700F7386F6F33BB1,SHA256=212DF1E5BF7BB3BC0ADB73B54ED2445DCB5CBFF627DA9615869BD0A8D418647E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044589Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:24.359{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1BB0064D40754179180A0BC681D4B617,SHA256=D75356D0ACF181C637FE238E2267BC326C679C6361CF70435DB977D426F5D3C6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044590Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:25.389{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=402B640EA96FEFC016575D55EC949857,SHA256=550F5B58C0343E521A7E69FADDCD0664C18F6FB0378246CCE4E9B2E9C9B8C142,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025680Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:25.469{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C26660909BD3C45B1B2F27B10AADB157,SHA256=C65C273EE63A89399DF794013F9B979BE76CC99A423187FE2B4708282D1C5EE0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044591Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:26.420{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA83E42022EAAD02E124757956867E6F,SHA256=4CD4F45DC8ADF19A82192A590FB47474F8349467DD8CFAE55C5A4CE56390FFBB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025681Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:26.484{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A934A8F9A0FC34C3EECD4C59D5AA6976,SHA256=C688A113005EE0A211290662182CD58C04B82D52632813E011600BDD234E0029,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025683Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:27.500{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4579176A0B6C9AADB1084A4A2A2874E2,SHA256=DFD127D4391B39A84B5F6390AAB5FC15958AB332FB6BE56BE0275D395C80120B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044593Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:27.440{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA53C046CDBB9AC482200DD227A12DA5,SHA256=644A7A2CE9869A90C44703BF5F5C9BA4951FD0D05682AD7411F3803B23B20D89,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044592Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:27.160{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-100MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025682Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:24.909{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50904-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025684Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:28.531{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B1114CAA62FA9B536E3601F3744D8B2,SHA256=97D564D7755ABA2800561C25335F72BDCAAF193829D2AA6304BC824A1F8F5298,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044595Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:28.457{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=40195C295493DD8D64A48F23DBA0C3EF,SHA256=0A505D951D617C375936F77E31A11E1F286394EBFEFA021F1E9C72583C65CE01,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044594Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:28.174{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-101MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025685Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:29.562{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=438E26B00C7AE5B2121C10FDB6B8CEA9,SHA256=1BE6672260F608F046D71A2D1143FED0936F7ADCDE9CD482CF1732DED6C49322,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044597Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:26.832{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51648-false10.0.1.12-8000- 23542300x800000000000000044596Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:29.473{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC68C818046721219258B0C09AB4B65B,SHA256=8C57B3B1CBACAEB0FECC2CB2CE28EDE985066C02E8E5577354540CDB72575EC3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044599Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:30.487{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E73BA62F00F0791B9291E8A8EACCA915,SHA256=196DBA916A913369D5FC2AA2582BDE39CB33A5AD73F59CF52DBBFDF0369B9C86,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025686Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:30.594{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC7B620772A90CBBADC739D17AA7727E,SHA256=A9F293CC561FAB5D4DB8CD441E2BC267B20079DDEF72CBA6F2F2C4EC43FD5135,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044598Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:30.219{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044601Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:29.796{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51649-false10.0.1.12-8089- 23542300x800000000000000044600Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:31.503{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5250035668A27166A2781F016C03D6C7,SHA256=1B29495DBAB59706954E35E82618AB4DF223603F389044CE0E8C66DA8B21B188,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025687Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:31.594{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D71E984846045E04C1DFAAD0B0551FAF,SHA256=8BF96C46EE6519E64B924C341FCC2CE4C0BF708DCE7058CA77B8B0D9E5562F7B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025689Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:32.594{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F923A2D8162AA44AA300CD120B32862D,SHA256=38234A511A3F282BABC078B5C52E2ADB5C42D60BCA3C1FA1A6FB24063B440697,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044602Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:32.536{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE830DD5463BDF931293FE6DFF93B39A,SHA256=CBE30917B12BB20D010D10DB3156C51500F8362F9F1CCD58F20710BF8B9D09C6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025688Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:30.893{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50905-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025690Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:33.609{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E571DA31750E32E5421D546921F0729E,SHA256=131C4C2216B8528CAA38BC05F5C263F6F03FE77385C3B85A86B68D9FC3218589,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044603Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:33.554{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0071C3651BBEA58448FCDDF8374D3A22,SHA256=DF5D5B32422C870A49E339AA993E7440C8C495736DA5D1CC7CCB674F52CFD219,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044605Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:34.569{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3B51AE7989F06E7C42316CFDCB48D4BD,SHA256=F3E17E6DD00503F337A78C1C2447B70337AFD8AB942EE13011BB2E8E4EEE393F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044604Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:32.747{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51650-false10.0.1.12-8000- 23542300x800000000000000025691Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:34.641{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32E5680EF70CC99BE48B97FDC6BEE272,SHA256=5957EE0D955BC86EBB48405BCC5400E1359618F9A77131B962F447F27AE17657,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044606Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:35.585{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=500AD30AB4E45309D112346B4B5D07F3,SHA256=896D7B184217A8983144B697656EC6D6AECBFAB9707562C7F0A7D42DC1BBCC1A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025692Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:35.656{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA6DF8135E40AAE2132E260191943754,SHA256=314415A75B8E67E8504F914AE559E3C80B1DB0FB2549F4C99DA3B2FBC39DD39F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025693Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:36.656{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=488395E80EF5E221CCDEB3A735331460,SHA256=F3E6F36EA0F76795A7EBD383ABB10DD0952C7C3E530F8F5B5E84702B8A4C4F2D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044608Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:36.599{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E6B7F760B34B13310E30BBEEC3E93AFC,SHA256=C5B4A6B9A8DE4EEB612C14883BC172358661897524345179C006D5E514525417,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044607Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:36.215{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=52223B67D35EC82F75F8A312495C4BFB,SHA256=9690FFBE32BC8BD4F560DBB6E4B965E2F4BF6D929BA68BDEE7E185E45E966B5D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025694Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:37.672{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=741B607AB5C1180485C8DB6C96C4559B,SHA256=0DD7AA6C4180A7FC63D51AD53AA152214411C24D565D57B220F84377E542064D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044609Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:37.615{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E84212C7BADC97DF7C186A650C3E51BA,SHA256=A796D8127CBC561B1D6F9A126346BD392DE6862C4571A38171A786526374AB03,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044610Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:38.633{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97EC17F98314010F325CE87C56117ABF,SHA256=936F98B613839A7C7739FBFE0DE26426E1288A0B19EE41FF0F8C3F86B0D004E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025696Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:38.687{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=28BD5A30B6395A5B1C3B2149B065F2D8,SHA256=D347B2484760A92CF08C94CCD0A9682DD0B8992906653D49572B014E189EC863,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025695Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:36.081{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50906-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000044612Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:39.729{323FE7D8-022E-6136-0D00-00000000F001}9042288C:\Windows\system32\svchost.exe{323FE7D8-022F-6136-1600-00000000F001}1308C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044611Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:39.651{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=77A71E35686404F7283D0AC49ECE39F7,SHA256=C2FAE61B54BB99C410A23E4DAA195C5B9D7120B6F2A7EEE254B388A5774626F6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025697Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:39.723{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5314098C7D0CD97E9931AAA859E80F4,SHA256=6C63BE9B12763032BF5ED805A6E0A14FCF1AFD9E2C91DF5D7FAD500EF5E1CC8A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044614Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:37.827{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51651-false10.0.1.12-8000- 23542300x800000000000000044613Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:40.713{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53ADC6A35B7113446AC6ECCA20BD22C7,SHA256=E39672EBE3A84FCDEEA6E3A2BFAFDB7932B7D678063608D1AB13C0A9871CA777,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025698Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:40.723{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4DA9ECCD87AE4D5906282482FA006E58,SHA256=650AA37E9D0F368B7BA942E2C11642524ACF0C7AE732F2FCF27E9335DDADF930,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025699Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:41.786{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=633BF1D6AD9A4EC2E02A6C0B17808DCB,SHA256=C402D54774A757AE05AD39C3A5B4CA05C7A3A35828BC27EDD1E1AC052C107A96,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044615Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:41.731{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97EFEBE0D9FA059F2A21830986FBE30F,SHA256=154D0A8745BA6E29727368E2389BB3B5E46A04F115DC55C2BB2101707B6528C2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044616Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:42.749{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3322BCFA599E6C78C875334FB4AF82C9,SHA256=6925722B5D80490FB1658B4A1353E624368EA62401DE388EF6A7A40F21C70BDD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025700Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:42.802{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C5A9C6E16226539AF2A810666A2AC819,SHA256=F598019F31644B5C7FA5B65E922C37EA9A27FE8B0F0DE011AD584040CEEB0AD5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044617Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:43.764{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E22C16F2D18721E2408325F893D214E9,SHA256=E8EF059DE8DD314B99E482F3E58231BDCCBD5E9351E2DB78E81980F1B786E18A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025702Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:43.817{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=507CEC02BD327F7A50A6E54148AB9137,SHA256=C3A63A9D5A6E7B3D5C6A27949A098CDEEDEA9CF12ED7E81EE13B19D3ADC2EE7B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025701Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:41.898{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50907-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044618Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:44.779{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D4FA3D7FC7E681964D5B5B5A3CD33F3,SHA256=B656E00C5C475F3A5C97268440175E2A95B8217A3BBC58BBA321219CF3970842,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025703Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:44.817{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A28F36D242BC4C7B68CB6F3F36C3C16,SHA256=4A4CFC39C6C8266E962112B2F56033FB9D72577BD56E35D0C82EB8C7CD12AB48,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025704Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:45.833{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9DC849FA2EFDB6C280135D9E869436C7,SHA256=EFBF3AD740434DB453B7991FB82C9B4D3CA3E5287ED819CD4439E2F5CF08FB84,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044619Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:45.795{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B644D99250F0869ACE144CA68AEBF06,SHA256=6904B895F9142FABA1958A82DF0852F301EF4E2500D7CC543A31DADD1F00D4FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025705Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:46.833{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F07A30BA2C3097654A678A42D4587534,SHA256=E56A175E50B6CF9F730AEAB6A0E1EB51C2F3387684471733F68E593D45B43E98,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044620Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:46.810{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=963494D9E4209BBAC591CD0A5F942FD6,SHA256=EE82F6D5161D139FCEC2A2159D4D4C953CE074CB66692C70ADEDE6CD710C2194,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025706Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:47.880{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53C0DD0407B8DA94001EAA7F4EB5338A,SHA256=AEBC53923F7F5DCF77F8A0AFCB3B3992150C61E1389A005AA92119771686120D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044622Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:47.813{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=48D810264905315F5B79072CC2BBC886,SHA256=CA965946553428D0E26D9607AE6D5B8FCA5EBEFE3E9ABC59209185771C8195CD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044621Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:43.719{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51652-false10.0.1.12-8000- 23542300x800000000000000025707Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:48.880{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=57D4E416F199E32F3FF538E119FA6F89,SHA256=599C158E28669ACF0898B1EB242EBD40764E8C0A3B9B8D39C9447B9994CAC6DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044623Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:48.850{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1BB4657F4E5F30F852A47CF10E9CCAA2,SHA256=905DCBE22BD57DC5D4E0B427FC4E45F81EE59B05DDD3B560C9F0D0BCB3CAE495,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025709Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:49.880{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=054F298A7BEB1555866A54A62CCEDB11,SHA256=63DF5104025B5552E91175E7C45E4CBC1575AC509D3116712A0E730FF8B64109,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044624Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:49.865{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A98EE4648CBEC6E232B76C87229AE01A,SHA256=D56BE74B12C02A7756DE81A57DBD09283532226E0913FBB0C3FB9B8274F90D32,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025708Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:47.007{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50908-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044625Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:50.880{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D88413A687C2B29A9368F8257B7639A6,SHA256=F6E717C7FFCBE2E72E24B01A33E7E20A3BC2F4CBA2F3D0492B2495DBD37F3F84,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025710Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:50.911{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7A1C10B3245E9503F79A8C179436B55,SHA256=38C57A88A9907D3A21761C79D667E296A8C08C03FC805E17F3DFBC5425E85582,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025712Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:51.911{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD1B525BDDA88B3701E6E08573AA5B4A,SHA256=BF1F4D675F2067CADD11F26C856EEFDBAF57376804631DFC787BCB7C1061EFDC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044627Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:48.724{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51653-false10.0.1.12-8000- 23542300x800000000000000044626Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:51.896{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1DED31CDB05854E290F9D55AAE083B0,SHA256=C4369B4E993AC9BCBFFFDB016BA1B3C43A287E42C3FD5199E43016F8B416736A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025711Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:51.598{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=75B0DF5E25E0C0981503E17DA74F9515,SHA256=516D6F4FBC0870728A245B614B19C6A3308F722183103277CA0E99D832458626,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025713Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:52.927{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D97C4FA1104E00D70986391ED2AA9973,SHA256=9537A9AA0B9C2693DE7207888D529319CBB2A1DE80924CE4D10BCDF1E127BAA2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044628Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:52.911{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B4521597A5A6B0D8D9A3D218A79AD90,SHA256=0D4BADE317E9D2C99354B987F08861FEA55AE0381ED12C273CCD8E10C5AA3C38,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025714Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:53.942{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C4695F7302C6CD54C7C084E1A1845F52,SHA256=BAB37F739741A6EC30B8CD974B618D9A25E635E93DD438F3CE1EE569CB0BA417,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044629Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:53.928{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A738890913CE7EA5D18136D01B1D5579,SHA256=B756DC29D21D95CA0693043BF177A59FE95BBBD40187E1389DD7439B83E079FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025717Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:54.973{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=014DFADCE23FDE1B7F78E80F75A32A33,SHA256=78BB41EE1ECC6938513F3F2F699B92DF3ECFCE42D4B2655DF0CCD51A6FA69A92,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044630Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:54.947{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8D53857D6BBEB18B1FAD3FE5D9EEDAD,SHA256=D63219137622E0049458282E7CD0A6B68D6645111369AEAD1EA03E2156308B7D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025716Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:54.223{FFF7FB96-041E-6136-0D00-00000000F101}7883500C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1100-00000000F101}1008C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025715Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:54.223{FFF7FB96-041E-6136-0D00-00000000F101}7883500C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-0F00-00000000F101}948C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+b4d7|c:\windows\system32\rpcss.dll+8257|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044631Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:55.962{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4DB6B5FEE765886649E1B9A985F7E04C,SHA256=20AA87FD3BC0C86096071B31DACD762F625728045FD20036AB824E9063A7C95B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025718Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:52.960{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50909-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000044632Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:53.818{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51654-false10.0.1.12-8000- 23542300x800000000000000025719Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:56.005{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9ABE51C9055580465B58BC4B99B73B0A,SHA256=94AC7C550CECB329F1F33EDDEA8A686541ABCAEE458E93F043CD5585204C5F81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025720Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:57.036{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C5BC739AFA458E1435CB53CEB6644B1,SHA256=9A2DB68153EDC285224B16F4FCD3345AB557BCBD76C7967127A7F2EB88095E41,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044633Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:57.008{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9C0190048AED038878AA0499185EB2D6,SHA256=9E374CD159D1220D7E3F38B8D80467BA07E7A93E2FB4BE4ABD410D9B66A8D1E4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025721Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:58.036{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF2F7E86625D7935A2CB3FA23786B679,SHA256=49DF08AB1463EC87E6B0DBFAC031A246A8117E5459A81051A34DD01D688E32CC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044634Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:58.025{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=780B2653E8254C091998F41AD3586234,SHA256=255D2B971531E7BA44477ABF251E0F40A50315A6EEAD1ABA1865068DD6DA9877,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025722Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:59.066{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CABF951948B8828FDADA44FEE9E26FAF,SHA256=187421C21A9534C59A798E2FB36649059906D1DB2E19847959C1E4500C8DB276,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044635Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:59.045{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C815DA5091FECC71A7F7017B7DBDE36A,SHA256=E1ECFA244C07216DB6C79B2242DF8575475E907E6CEDE1D5B3F06E2EEACA7600,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044636Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:00.045{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F8266F93F14E8351D56915E314DB69C2,SHA256=6395FE1897906D4AC1741B2A916784FF3001B318DCA86353EB8283B52D8F5E4E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025723Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:00.066{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BDDAFE2CE9E0B300A62EB7C09BCF9ED2,SHA256=139BCB01F2C6172361F3C164A96285C7B312CA301572F3F77C50FFD7C25FF4EE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044637Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:01.060{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C8D0571AE54B5E37BD13F74D1D571B4C,SHA256=37E1501853A22FBCE523BA4473025536D27362BB814DF212AC0E0E68F1FC5178,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025725Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:41:58.959{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50910-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025724Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:01.129{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=225B5C5D83994395373FD3C6CCDF7CCC,SHA256=429EC53CBD0F7DDA774B4FE59EDE8BFF126096F259B033637008FF70E6BD5EA7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025726Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:02.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F4D9783648FF1A66E94037D9F9891A46,SHA256=0D3644CB0628A4C03AA449409CC8FA6F75CD68D4E78A93C5926B5296CAAE522F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044639Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:41:59.768{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51655-false10.0.1.12-8000- 23542300x800000000000000044638Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:02.074{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4665535F1D94AF979B4DAE3222861223,SHA256=E85B8F6F4514292375D9BD38354B27334C79B59145742B21F1E72955E264830A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025727Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:03.207{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BF13622DDA92ACA85ABC02A8AB477CC,SHA256=6536B4085D511144CCB056CA481F955B89F61364D232D7BB7708CE14FFD6E228,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044640Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:03.105{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C2C2679B6B3302AC7EE4177C51C700F3,SHA256=61F214C4AA94013804C5F6243235DFC97C3EE7AD6C5B1FF38AD7AB103D251D80,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025728Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:04.222{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=79A7134430F083BF42C85102A76283C0,SHA256=9C41D670FAE4F59D9E81AFC0FCA38933DC1E1793095801E92AE48D8E073053C2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044649Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AAC-6136-DF08-00000000F001}6148C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044648Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044647Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044646Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044645Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044644Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1AAC-6136-DF08-00000000F001}6148C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044643Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.441{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AAC-6136-DF08-00000000F001}6148C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044642Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.442{323FE7D8-1AAC-6136-DF08-00000000F001}6148C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044641Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:04.122{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02B8E9D0CE7EDD5A44153682B4FD2179,SHA256=8A58873D0E7D033C57BD78D4F33F4E2BEDF51C8B45EE108B5D4B2FDAE08DCB05,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044669Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AAD-6136-E108-00000000F001}6328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044668Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044667Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044666Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044665Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044664Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AAD-6136-E108-00000000F001}6328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044663Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.711{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AAD-6136-E108-00000000F001}6328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044662Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.712{323FE7D8-1AAD-6136-E108-00000000F001}6328C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044661Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.442{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2D3099CC7923E2F0469E897B73534C87,SHA256=04ACDB12F0D0E70DC6C8213AD4EFA4E3A92A0555C5041FB875F871FCA2E828D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044660Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.442{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=09F6D627D949A1F2D11E09352E7503D0,SHA256=8DD1E7002E752163757898FDFA912388E2DC64624A9B1F7959636959089CCBD0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044659Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.342{323FE7D8-1AAD-6136-E008-00000000F001}6285688C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044658Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.125{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F64628117313416D030DA521EA174B30,SHA256=173615776FD61F87CC7D42AFEA5253E1DF85C12C371636328DD513A7BB8B095E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025757Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.722{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025756Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AAD-6136-5906-00000000F101}1436C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025755Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025754Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025753Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025752Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025751Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025750Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025749Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025748Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025747Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025746Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AAD-6136-5906-00000000F101}1436C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025745Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.707{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AAD-6136-5906-00000000F101}1436C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025744Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.708{FFF7FB96-1AAD-6136-5906-00000000F101}1436C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025743Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.238{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0E7321813C45E18C0516E5AE7555D26,SHA256=001BD29F991302A5D98685357B1C75EA3450EF813AEB603CA47F039F491C9CF4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025742Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.222{FFF7FB96-1AAD-6136-5806-00000000F101}26482784C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025741Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AAD-6136-5806-00000000F101}2648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025740Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025739Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025738Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025737Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025736Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025735Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025734Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025733Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025732Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025731Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AAD-6136-5806-00000000F101}2648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025730Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AAD-6136-5806-00000000F101}2648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025729Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.051{FFF7FB96-1AAD-6136-5806-00000000F101}2648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044657Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AAD-6136-E008-00000000F001}628C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044656Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044655Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044654Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044653Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044652Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1AAD-6136-E008-00000000F001}628C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044651Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.040{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AAD-6136-E008-00000000F001}628C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044650Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.041{323FE7D8-1AAD-6136-E008-00000000F001}628C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000025774Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:04.897{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50911-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025773Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.347{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39965DBA724F385D5B1B0C9220A465FA,SHA256=A685B737449871AFD9805A8C59814CB38EAE6B1F4669A6D7B6FA588CE0AC11A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044671Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:06.612{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2D3099CC7923E2F0469E897B73534C87,SHA256=04ACDB12F0D0E70DC6C8213AD4EFA4E3A92A0555C5041FB875F871FCA2E828D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044670Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:06.161{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=116FEC2EE3A6C2A42F4A9C8C94B674D0,SHA256=817D9F4F866BDCF863FEAE43EEBEEB89200FE2FA47B06E62A65D52DA0B2DB7F4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025772Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AAE-6136-5A06-00000000F101}1640C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025771Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025770Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025769Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025768Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025767Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025766Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025765Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025764Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025763Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025762Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1AAE-6136-5A06-00000000F101}1640C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025761Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.207{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AAE-6136-5A06-00000000F101}1640C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025760Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.208{FFF7FB96-1AAE-6136-5A06-00000000F101}1640C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025759Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=762873D70575AF41A5E559EC739C1A96,SHA256=9BB029B8DD117ED3CDFEE1A7804CEB2C3071AFD6C280A4EF117A46BB3645BE52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025758Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:06.176{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1379DC2AEE765EF9184B961A5173DF68,SHA256=926A5623EDDACDAA8D2B40DFC2058053B28946798C60D888AD94611CEA6C1EBD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025804Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AAF-6136-5C06-00000000F101}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025803Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025802Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025801Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025800Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025799Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025798Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025797Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025796Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025795Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025794Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AAF-6136-5C06-00000000F101}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025793Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.832{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AAF-6136-5C06-00000000F101}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025792Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.833{FFF7FB96-1AAF-6136-5C06-00000000F101}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025791Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.535{FFF7FB96-1AAF-6136-5B06-00000000F101}26403588C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000025790Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:05.553{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50912-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 23542300x800000000000000025789Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.379{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=762873D70575AF41A5E559EC739C1A96,SHA256=9BB029B8DD117ED3CDFEE1A7804CEB2C3071AFD6C280A4EF117A46BB3645BE52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025788Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.347{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A910ECB42B26E32EA9EF96A79F3E96C0,SHA256=D2424398EF5AD1672C2BA5510633F2222D2B2316D65D9A5DDA2F1C5A5B7A3B00,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044682Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AAF-6136-E208-00000000F001}6708C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044681Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044680Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044679Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044678Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044677Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AAF-6136-E208-00000000F001}6708C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044676Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.991{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AAF-6136-E208-00000000F001}6708C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044675Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.992{323FE7D8-1AAF-6136-E208-00000000F001}6708C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000044674Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.189{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51656-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000044673Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.189{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51656-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 23542300x800000000000000044672Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:07.176{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA768826B75158C50473F6BE8B82DC49,SHA256=E0DD380F50468442EC10180AF867E74E0CF0EC1026739658737467C3DE7A18C4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025787Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AAF-6136-5B06-00000000F101}2640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025786Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025785Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025784Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025783Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025782Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025781Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025780Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025779Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025778Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025777Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AAF-6136-5B06-00000000F101}2640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025776Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.332{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AAF-6136-5B06-00000000F101}2640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025775Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:07.333{FFF7FB96-1AAF-6136-5B06-00000000F101}2640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025821Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.832{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F3C1239BC63A04B99CD5AD34AE6E462E,SHA256=BA4986BDF4F4E1C7C49A2ABBDAADC5514C55867455C561A4AC62EB3A9017A803,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025820Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.660{FFF7FB96-1AB0-6136-5D06-00000000F101}33003416C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025819Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AB0-6136-5D06-00000000F101}3300C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025818Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025817Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025816Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025815Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025814Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025813Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025812Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025811Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025810Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025809Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AB0-6136-5D06-00000000F101}3300C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025808Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AB0-6136-5D06-00000000F101}3300C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025807Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.504{FFF7FB96-1AB0-6136-5D06-00000000F101}3300C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025806Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.347{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=92C27CC8ADEEB063184656222F94892D,SHA256=DFCB3A0DA38BEA3FD9681E12F031393CF671D951A122E0F3F171A3EBC6E68010,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044694Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.813{323FE7D8-1AB0-6136-E308-00000000F001}32964984C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044693Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AB0-6136-E308-00000000F001}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044692Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044691Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044690Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044689Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AB0-6136-E308-00000000F001}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044688Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044687Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.660{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AB0-6136-E308-00000000F001}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044686Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.661{323FE7D8-1AB0-6136-E308-00000000F001}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000044685Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:05.754{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51657-false10.0.1.12-8000- 10341000x800000000000000044684Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.260{323FE7D8-1AAF-6136-E208-00000000F001}67083368C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044683Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:08.213{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B86102FFEFCB40F5882B90B0CD31918E,SHA256=C5E28A39EE3470268E74FDFC7563982708060FCA343ECC51758D0A77829E9B3F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025805Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:08.004{FFF7FB96-1AAF-6136-5C06-00000000F101}9882960C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000025835Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.660{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3DAE87339BA3AFDFA870EF3212AA7A41,SHA256=48B4A75BEB1104AD73762BE86D9383EAD044F8D1AEBCE1400B97691676618826,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044713Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AB1-6136-E508-00000000F001}6428C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044712Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044711Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044710Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044709Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044708Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AB1-6136-E508-00000000F001}6428C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044707Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.928{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AB1-6136-E508-00000000F001}6428C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044706Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.929{323FE7D8-1AB1-6136-E508-00000000F001}6428C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044705Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.412{323FE7D8-1AB1-6136-E408-00000000F001}64244376C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044704Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AB1-6136-E408-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044703Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044702Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044701Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044700Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044699Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AB1-6136-E408-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044698Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.244{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AB1-6136-E408-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044697Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.245{323FE7D8-1AB1-6136-E408-00000000F001}6424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044696Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.228{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5C67E4D7EC4DE862FA1E9FC72AC6F84,SHA256=FB58065B0F1C05865333BB4640594416FF45A3ADD883AC560597D5C7E88F0CDA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025834Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AB1-6136-5E06-00000000F101}2272C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025833Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025832Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025831Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025830Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025829Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025828Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025827Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025826Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025825Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025824Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AB1-6136-5E06-00000000F101}2272C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025823Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AB1-6136-5E06-00000000F101}2272C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025822Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:09.176{FFF7FB96-1AB1-6136-5E06-00000000F101}2272C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044695Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:09.010{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0E3A56DB46CB735B22F8511086C36BAB,SHA256=B20B209F7E8E0A09CCDB8D43C823D3FC1C37C95977DCB063C1CB17C8C6641B95,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025837Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:10.676{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9F8CA343345438A732BD26A79EDA2B0C,SHA256=45DB8259BFF2AE3D97B921C8DA9EEB416203DA08A01851A8B4F584D9D9842754,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044715Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:10.259{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C353D164C56F5A73D6C6D28FFE3BF1F4,SHA256=0DB85AD8D9DB24930E4E85094EF05B6DAB3FC02D1A248CEF36435751F357C44E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044714Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:10.244{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9AE80D3089B62ACCDE3A28EDA629EE83,SHA256=D4F97EC587C166A1B390850D1C1345EDD2E2A9ECEB6A0DE1C78CFE22CCA5B116,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025836Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:10.191{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=02461CBC331006C3111DC0698C122B19,SHA256=AA7839AF783495EEFD0D6EE707153FCBEEFBCCE683A470229B203F2F497E8BBC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025838Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:11.691{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BEDA1AE68B09AFD95EBB2D64132C83E8,SHA256=00E84613BD5AB3BE28FBE4E860CE8B3D043909B49FF13297892E4536C0FBB211,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044716Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:11.259{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4208189E3DD0CB1B3E2D728C3F3F85BE,SHA256=98B17B9F72923A834DE49EB23DFC834547F7DA1E65A6CC841A9EF6A96E504134,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025840Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:12.707{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=039C6BE84C79698F7E066F78A7212439,SHA256=7558709CAECDEABE4FAF91DA7589EDF8415B2928FF0C51C409403BCC1A8F8477,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044717Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:12.274{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97034157DEC2533266662D09319DF18A,SHA256=CA775F819CAA978A917BEA14715E1738F324AF5AF98C8AD2F4372179D822CD5F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025839Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:10.084{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50913-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025841Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:13.754{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3C8CEE597CDC1F1CE4A05DB7F4FC8152,SHA256=3B21A77248AB8558E1D3B0DDCDDC62F532BC076F71D18AAD74C888BF4A0E9D3A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044718Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:13.308{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B30EAD718FBC8364927B4ED2DA88914D,SHA256=474191BF9E7F43E2C0C01D73CCA829C3DFDC718CCE157A5701CA4CBD0874E667,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025842Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:14.816{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B1D009DCAD1D86EE39FCEC129D0FE8AC,SHA256=7BB27E016ECB0AF4490E6FB6D882B62A3B0B26902B8C20D3927ED3376B35C41F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044720Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:11.751{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51658-false10.0.1.12-8000- 23542300x800000000000000044719Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:14.342{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B998CEAE1774E03225890C5140A9A113,SHA256=ADCD5482AD161890F3D259367EF541BB06FA41C74B17FC6CC18312374058B820,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025843Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:15.879{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=881F87BF96422ADC2AEC263AB5965E76,SHA256=74069A411B9FA42962E4B3965B0754DAF3C66DBF7BA2686A97D4C5C71F1091D0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044721Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:15.373{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D2B8D1CA2196398E27F2280C05A9269,SHA256=382C4AFB8DFE7AA4692297D085C94A9050C6142C6F2892AB1BFFBA0F98D03BF5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025845Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:16.881{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F496E31D84DD8D1DE93AF86D78867D5,SHA256=4C5D2968C0686F8E53D1A9ED0B798208543D6512D4818BC1D3DCFA0222D28A1A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044722Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:16.406{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E1B451B2B4844E1488FF1049596755B,SHA256=748D88AC9F8098DED541749D7502B89EEBE13D96C3CB8C74654C0FE6F2DEE8CF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025844Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:15.085{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50914-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025847Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:17.896{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C4F17E1717145446D0683BFC916DB19A,SHA256=2DA5685F2D6E977384F6595C1BE04FDF291CEDB5F7E70FBBC52B39FAE08E3955,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044723Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:17.440{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4E75FC6070C122F5661A4A5C16DFF917,SHA256=7267945A6A62DBCE12F229F060FC57DFA533216C57E5753DE8896519A658C611,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025846Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:17.024{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-093MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025849Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:18.908{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=59C9D6336A0BE3E6A34D7963C470377E,SHA256=1BBB1835FC71BFA7114A4341AD7CF4D2DE1B1BC6CFDC5C7388C55259BA6E38A9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044725Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:16.795{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51659-false10.0.1.12-8000- 23542300x800000000000000044724Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:18.471{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=494C11A9DA4FAF390DE6EA5758737E66,SHA256=30DFC59B32CC336EBEE0EB23A8664AB388F97A59CC3AFC0426E441882B587D2B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025848Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:18.038{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-094MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025850Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:19.924{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CFFBCD44883AC518A010EF6AC1BD3484,SHA256=F6EF447EA0517B9FBB64FD9AA35C2F8440CAAED3D69C5431B2F7C0A547AAEBBE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044726Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:19.486{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=92570D8DE51B784FC0D2466A63F0F6E3,SHA256=E920EC888AE8E0EB34E9B8FA793133CD02E09CBF1E5369E941766F1B4131E7FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025851Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:20.924{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C82F1C2FEB8F7630118D92EC990BBA44,SHA256=B3144BBB553C239A16C036943EDB312D4D10369A4B4817D034E5E5B6F5998A2B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044727Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:20.503{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=034559951BE5BBF992F11E249B952436,SHA256=677951BAFDEF6AC8B2DECD0F4C5AA7C2D9D32B4FE3EE6B2D16CFBEF4B0939AA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025852Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:21.924{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27A1E87FEA1124E50BA7714D06442FB4,SHA256=E1087A4770D03A368B481C0D1239EB5284E68502C3DC14F91C003BE5BEBE2F92,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044728Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:21.522{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D60161FBDAF231CFCE28D384242897FC,SHA256=28D7366C76CA1CF7FB8F1564CFCEBBFB6BE9F5AD839F30F1A47CCB26B5D1FEB1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025854Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:22.924{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D70E6008976C9A1093C021CD77AF2BEC,SHA256=4D34193D5ECD479764D1D20DDE33135E6F0A595DE2CA81A4FCE5E7D2CD81BB83,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044729Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:22.537{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C86A52FA90B8D926789C4B149EA067F,SHA256=44320A4411E29E2ADE148B36CC553CF7E53770EF392152AC731EAC751CD9DB43,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025853Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:20.958{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50915-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025855Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:23.986{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB1A92B8F7A4A0EA24C68C153816B4C1,SHA256=A16EDCA12D1351B3701CDA67ADB39CC0075EFF42F7A9475A12E6DB1F9C1D4D9C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044731Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:21.814{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51660-false10.0.1.12-8000- 23542300x800000000000000044730Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:23.552{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21673AD53932D5F91BFB06AF603B5AE0,SHA256=A406F636B9BCDA0E253504DA2A7107EAE516F0455FDB3693D4F14AC67F34AF81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044732Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:24.567{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA79268A5167459244DE94BF8EEDE9BB,SHA256=1C0EE28E800C2853198BC0E51680A6915622AC3BD7AE93548E1FE118512A6F9B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044733Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:25.582{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05CEF89364128B34C2F7B404260385BC,SHA256=CB9E18B5EED5D27D7F9A6DD70B0DFEF17C39B879A3927A7C01540364A36C6589,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025856Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:25.064{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D44CE17507DE160E2A18BEBB24CAE7CD,SHA256=1E5EDC65FF6CEC434571CB9B383858A17EE2D4E6C61907590203645E1CC97764,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044734Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:26.600{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6E2D15E855F40D380B8749600A58D55A,SHA256=7ABB7D87380773F8557B4F5A185A19C8FD19D0CCBAA7D2CD58A1B7DC2067A3B7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025857Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:26.064{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A733AC25BD9BDC4C543FBD7AB5C5F714,SHA256=01CF2B2CDD23A415DDEC8D5750023283C0B8EA79B17E26D2ECD08375741A5FF6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044735Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:27.618{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0AC8207AB29026D408D59871D044D2A8,SHA256=9F09E70255A063C6658A884FDB2EDC7B4A3C38A0BC9D529001DB94B47BF5C595,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025859Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:26.052{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50916-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025858Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:27.111{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2EF7307371704DAD93E145C5A7644296,SHA256=7DB1CD6D1578D088349410906EA6C7C3FD3BBE18F1B119D76336E0801A4BFE1E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044737Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:28.698{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-101MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044736Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:28.649{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16958B31688E32121F99DA2CEF8EC169,SHA256=3C4BCE8B97F0FF07742D05FD905D77ABDF891F227BBBECF8ED3F12CA79EA3E01,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025860Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:28.127{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FF6DF8EAF164AF7C81EB59FF0FF7DC7A,SHA256=763994C57916B045881FF6BF9880938B764F5F1109D9F36FD63E76E41D8CC9BB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044740Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:27.789{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51661-false10.0.1.12-8000- 23542300x800000000000000044739Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:29.697{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-102MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044738Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:29.664{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9BCD81C4333E717A9C49AEF54EBD467,SHA256=4469B3905EA9EEC0B875BF14852D1CBEA19841B3DE7B38199C461788857E63C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025861Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:29.127{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E4FCC90A2158EC30BD79EA067D37E9D1,SHA256=6675B29872A8FA145A9CC755F817980F3C86BC6497A19D9A4F9C0F8ECD94A840,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044742Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:30.679{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5D7BC4246EC03F9E99BEDCCBC3279B5C,SHA256=13AA4F4C0873E41CD98A28F416B573B3A1D3B4274EB79646A696D23EBE3131A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025862Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:30.143{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50FC0C9398032069B4905B8B27734A0E,SHA256=81DF068755222FB87D65355F3D8FE4736DB319F1F24FAF6C3C8C313331464983,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044741Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:30.238{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044744Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:29.813{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51662-false10.0.1.12-8089- 23542300x800000000000000044743Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:31.715{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6FCB3B6D0DDA072C8F05304F747C853B,SHA256=9FBA290E8C022354F516326EDDD18DFA542EF64061AD93F819420797D1BD3053,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025863Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:31.158{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5EA13FAE0B08E82C9E453B1E234F7069,SHA256=7B06D6FD9E6C88D2711A99BA58AE4CE51C95B02A97EEC6B33D0E8A7798F2E85D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044745Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:32.746{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97B8CCD112A7533A4C84DE42E910C0CE,SHA256=4D40F184AD76FC6EF89322E2D2A7F64C7D2CB2BC20F93C43ECED16653403ED38,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025864Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:32.158{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F42C8BE6303A816D942AC44D7A51F8A5,SHA256=A6D2AB14FD8F167FFC92F9B540032CA9766F69F368447AAC84512C659A7F1B68,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044746Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:33.761{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=890072AC4C2C68BE439D4B0DC30B3C43,SHA256=62729C323BB4CE10CAC679611F7D034708B034E535695ECCE87F93EDFD83BF6B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025865Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:33.189{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BD6650133B05507BD40D7C3AB9AC7C5,SHA256=97D0316A1A32FCDAA50B0B627E754A8F213D1EFCD2AA4AD3E4D55D7AE3D01B37,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044747Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:34.776{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3731994DBE554AF8A223D506C5B3417,SHA256=7C4F2BF6F59A40BB7B78CC2090831A2CF6EC96DC5AAED6AE2774DB7EBB133F5A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025867Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:34.189{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=955781ADA8E3ABA3BB1B333A8A70C715,SHA256=BD63F636552A5D7B82E9C784FC1DCB38A113A6FED65D0B86E8EC574439D4F00F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025866Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:31.864{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50917-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000044749Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:33.806{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51663-false10.0.1.12-8000- 23542300x800000000000000044748Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:35.793{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5D443B6718BD25F8718275AC39BAC6B7,SHA256=59A7A262706C64181DA8E08A0151B048F08A529BF9DBA14D89275EA65610CFB0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025868Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:35.221{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F52993B332C45ACB476B7242966BCA38,SHA256=26CB604C7C205320812C946E8874990CD2EBF7E6E4766BE5F4EE9E4D7259F58A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044751Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:36.812{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=237D8232607E3BE13C728AFA5B6EFB75,SHA256=093C962C553DC24A6BEF6AEDDB7507B89DB260A6782737CEDD6423F754217001,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025869Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:36.252{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0620CFA10CC317C39A3C3DED75708ECB,SHA256=CB75D6910FA34FA523F6793A136F403B135CC8D65F3104FE78E76D5BAEE6FB32,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044750Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:36.228{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=1F7FEF67149EB14DB22A4E8AD0CCC008,SHA256=D2DD9C3860523BDF15DC7A500423F3930EB2C1BF21091B2A93842131FDC77DCF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044752Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:37.827{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D7F4381292EE8C6B60B55B7B1573335C,SHA256=E7EB4B1EFDEECBB2607036C08100411BD0AB211B88842CF5C4CF07D4F6C635EC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025870Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:37.299{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA591F5391B93F928F53D39B978D8A6D,SHA256=951AEA5EC0D2705B54ED087C12E511045D701C31F7731E286090B0654E1FB668,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044753Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:38.842{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18FD16FED9B7C2F33FFDC93A4FBCD068,SHA256=EFDA510A475F824A369CBA097297159C6C194E4AC27888903540D8F96B588752,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025871Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:38.299{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6FBE17E2325A912BC6E3E7B50A3C0B84,SHA256=FE271E475257B58D2D88914AECEBD800A201429AF31E29C8626C7CE3D996BB21,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044754Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:39.872{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F41303DEBAE53BC1354DD995126445A,SHA256=BAD65574260CC4245D488DFEAC349427584E675AD5894758F15AA689E9FD5ECD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025873Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:37.864{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50918-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025872Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:39.319{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1794BBF1525B34ACCFD2C2F936F417E4,SHA256=39A16E0F9757D26D15E22A945FE1AAC62C115C720B3DE349E0DCE72665F612DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044755Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:40.890{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BE5569B26EA19D5274F492F0CAE4F6E,SHA256=368FB40D5B918751FA78B65D04BF132E891AFFFABB52BC0A2D61907F71CA1072,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025874Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:40.366{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E6B690B25B66112B28EE9EC354793B3C,SHA256=987B4188DC4CEB9FE868BE3328C23914E6C91AC1FDF63BF1BB652EEB5B3AD98C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044757Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:41.910{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=59449804ACF905558138522F2A2C0001,SHA256=57D538E9CD8ECAC1E2F438A4F7E153271BE45DCF327B7952F3F90AEBD8F6E1AE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025875Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:41.382{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB3100A60F8B62E6A82129AFA2C7DEE1,SHA256=CB87908429A5DA8F24C277621F074F64A36D878C585D0EF496A5FBED4DE85C10,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044756Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:39.784{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51664-false10.0.1.12-8000- 23542300x800000000000000044758Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:42.940{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2AA1725C94FC6893716F10AFE8975462,SHA256=DD79587153066F5CB85C9505873B1B0E333C62298B2F40CE3B76CB0BC5EB5FCD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025876Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:42.397{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6441E2B99BF055AFBA9BA8D7961842FD,SHA256=896EA8831A8F97D9668C9E605E76E8AEF6F3FE05349E9B5D875BD1229414F3E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044759Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:43.971{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0820C5B8491B6286570C583011504AEA,SHA256=313AB49C8CEBC492656C63FB3D6094EA028B12AA979FE8868A40962B7C9EF344,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025877Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:43.428{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0242BC9D30EFE6023EF6148683FD373D,SHA256=B641A518581A24845C07662359D0842B67ECC9E7ED0698D3BBD033FB67FECA9A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044760Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:44.989{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB0C2A50F3DBD932A73CE2FDB6E5DA8B,SHA256=63377161865D08FF1579A439F205C2763938F962AFA6A73CAEB4A666EDE7C29B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025878Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:44.444{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=01AA70AA7033E346964F8C5F47042737,SHA256=E04FE9EBA8C252E0617A3ED257AF18EAABDF6651E7257D184C55B2FE0F9B4845,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025880Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:45.460{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=333511CE97610CA38C0FD5D04961BCB1,SHA256=F6EF3F88D3543697AA7506FE754F4E11BCC29AB66FE7A5EB659ECA189025E439,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025879Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:43.025{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50919-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025881Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:46.475{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=29DD47BA38861D64EE9D011D979ACE8F,SHA256=9CE6A386113E5BADC7C6FC32676CE5C97E60DCAB9E56D4BC326F9428245F357D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044761Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:46.007{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=565FB34752DB9B108211C31E59899670,SHA256=3E96C523A461E9F19726BA663AE7F8BE143EAC8FD7E23FD12274E77B71EEC749,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025882Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:47.475{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=896F0B7BB18A98B6E7E9A8CFB9E72D1C,SHA256=322F48CBABEC2FDE427F607DB11A9BABDCCF45369573F19DC0D2E453747558CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044762Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:47.037{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=438B9B31D359817D533EBF751B0D96CB,SHA256=22B25429A1F02983D57447712EDC6E7DE6198FA5CE5D8F5AB4E5252E28AB2377,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025883Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:48.475{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F44588ECAB60A3AEDF3B4F3C25A025F0,SHA256=D8E5B62E39F779BBDB6378959A2946B785376431B568422B3BE682BDBABCB3D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044763Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:48.037{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=56FE0597D2BA9D247AC5FE240D06B064,SHA256=6F5494C5CEFD7340830500D7E1A7E0BFDD6D0278715619157B40ED19CC686070,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025884Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:49.507{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A43A505DF645CCB2B798C7587D2202C3,SHA256=4EB3454BE25E65605766E403F7B72837874A0151068B452C409D4A8B3ECC0C35,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044765Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:45.714{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51665-false10.0.1.12-8000- 23542300x800000000000000044764Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:49.051{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A7A25CE74501C37C736A59527E91D66C,SHA256=3258DEC4490DCF61753E07AED86FBBEB9D0A1AF49E5EFB8C0DD74B5A22017DF3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025885Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:50.507{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=01D61034954599BE3C33383B1EA7C271,SHA256=5026A18D9AA02F194445D1DCBB349E5D3AA85690F883DEA827FB836E7FFB11D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044766Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:50.067{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9CC8E8B9437366EFAD86DBE32C404047,SHA256=FC2D32B985BA07D523AAFC7A9858AF05AAF97EC143DAC6297322C8168B324BAF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025888Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:51.600{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=A2B43E61ECE225EF12EFA0F34E78C0D4,SHA256=3CE13CF975FFEA6EA89B4D95A094AF164B734B267772ECF88BB8511EB8DD4CA8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025887Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:51.522{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4CEE63C1DBEE8E785AFDB9C524CE0E63,SHA256=A5CF53CA417A00EB4185C041576E9BBC9DA91091FD147E7789D65CAC30CB9299,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044767Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:51.104{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D1C94DC55EAFB289BBD04CF192AA0D2,SHA256=6A10298DC3BC0BA67A1A097CA58DE7FD656C4DDE8D9922491BB2E0F207C00367,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025886Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:48.947{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50920-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025889Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:52.522{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F5846A2165A0E1CF854226424F447A8,SHA256=B8147F8B5923D75CC2864775F6C4A0BBE234AE655D29B35DF301612ACFAB45C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044768Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:52.135{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C20765FD18441ADB12EAAA50BFE4978F,SHA256=F1C0B2E73C4C4AFCFB2432C8447922B1481A31A293D09C21D8DB15F2A2B459C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025890Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:53.600{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E95353CAD2727262CE80EECAB58F02C4,SHA256=0CAFC2BE04D30F855D0F1AAD6AA33853EC6F042BCBA06D49CB9F73E61996E26C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044769Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:53.202{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BEB603608546D95AC1FDC2592A3C437F,SHA256=DF52B71D465C409CFB596A8301E0A6EC63B12F13394CF6051C4194675D6E2B6C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025894Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:54.600{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B1282089E00B8D02DF98B3B8DA375DD,SHA256=C7479542F455AF67BB1C6E6DE65CDDD2A6A77FDC9E2154300CF30C706D399534,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044771Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:54.333{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=292A91E53BD6EDD38EB7FF8D17F4D0B6,SHA256=599457797A08E07C685E846BB3495B9E992C49D217AF384E23EE5D5B0BD29859,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025893Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:54.007{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1600-00000000F101}1252C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025892Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:54.007{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1600-00000000F101}1252C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025891Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:54.007{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041E-6136-1600-00000000F101}1252C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000044770Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:51.711{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51666-false10.0.1.12-8000- 23542300x800000000000000025895Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:55.616{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E4F87775A327D3EAA144804918140D85,SHA256=6D7D68E14CDC7974C3600F1D0F6FCF7A2935A1666B734607AED5A2E7C722B9DB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044772Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:55.364{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CF605FBCC37F4D3897F2BBE20B1E8D45,SHA256=2821F03F120210CA5F8663A7F77FD37C1E299FD03BC839EC12C4B6941F3BB7C1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044773Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:56.401{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67CFF1D870590769066AD60DA5E20E14,SHA256=BF7198D721AB9AAA8EFD5115F3E57A50ACC49AC77A58C7DE113FFE8EBE45852B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025897Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:54.025{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50921-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025896Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:56.616{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2801D7060FEBA8580F74116A9A423A93,SHA256=F5FA3BCB35F2695869A83F27833274B248754DE12EAEC8311C304B4D1045F868,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044774Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:57.431{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5BCC785E23D90FE3E7D16DBFA7DF87AA,SHA256=2DE7AE4834BAC36C4C708BCB15B14078ED0422749F5BB648EA77423B311387A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025898Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:57.647{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9F8F4F9E019CC1D373E4F43A81DD5B7F,SHA256=2AF3AE36166318E0D7D1B3EFDFD517761ED497F60FB55D1CBB3597D1442A0D26,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044775Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:58.481{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=28E840BE5CE71CCA7D58542F64AD5480,SHA256=DE275C20218DBD6C31AF2AB008C7BCBFA5F17E42655F093704FD14C7442BF070,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025899Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:58.647{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0C3D6F72A6F651E1EF0C9CF46733DB1,SHA256=10971E486ED2148E008DF01FCF0EAD4EC33F9325732F19E1ACA076A0BDA3052F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025900Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:59.683{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=63286B1CB0BE6F1CAEFCE988632AF94C,SHA256=E081864BA8FFE194B71C85A3160CBEC7173294A0D3913834DB620C3316CB084F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044776Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:59.514{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=007642C02E42409D766D5144DBB5E192,SHA256=4C46E6A290417E5FB3886FA34D4C1BDB072319966B6CEF2E9C02F6705C490284,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044778Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:00.530{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=797C9605F1F4D115DFF8E53D56023BB3,SHA256=B98E599528019D9E27842DF1D13A22E0E92D4FB27AA18680FA063E95650C4D51,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025901Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:00.699{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=42D83A79F7F25AA67FAC72C6D7BAAC9B,SHA256=863D48DB9D3C592740EBF40140EF61C64D225BBF7F38B2B301D56F4684E0EA2C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044777Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:42:57.707{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51667-false10.0.1.12-8000- 23542300x800000000000000044779Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:01.560{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7668CC0B631A7FB0BD90336D9BF8340E,SHA256=CCB910DAEF35393BF6A0165FA113E6105C8BBB5F6833AD1FE850E43F1A38671A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025903Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:42:59.967{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50922-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025902Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:01.715{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E2839A6E5690A03C06C0C0EF1F76125,SHA256=1184D662120F2EE99BA56BEA0B7E600743DAE6057B513B88FB02C51979ECD107,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044780Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:02.578{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=333702F8EF952A5A524FFEAB48C03F3D,SHA256=5ED31FD31639833A7687307171A7045727DE30717DB529AC6AD0F370409D605B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025904Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:02.730{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=25CAA6F4C189872082344ADFB8EE498D,SHA256=38CF96CD6FDF1B9288D71A23607690A9DD0478F8FB368844528A6A3DF6AB7A6E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025905Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:03.746{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A504892826B50E4B8FC803BC7E4DA17C,SHA256=E3D3A69D1D60935BEB2168141FCA73426B0E4ADE0B0D6125B7AA5076A14C2EDB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044781Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:03.596{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C444F9FC34F01D96E55B817283C1CCA1,SHA256=A01D4876351C67F973920DA6103ECA461D204030FA6E37A3185A05DDA8CD1CFE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025906Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:04.762{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE5F2C27A51605847B7CF974E903A7DA,SHA256=F085CD6C67F8E9D005B08C4FB51DC53F1D60D048A2B9DC75823FC2F17D5953BD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044791Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.699{323FE7D8-1AE8-6136-E608-00000000F001}16083584C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044790Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.616{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4585B0D2973450ADBC32389C6A5291B0,SHA256=497C508C09ABC643EEBE6B92295E3182B8E156C2EC781615644B9CD84768AA56,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044789Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AE8-6136-E608-00000000F001}1608C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044788Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044787Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044786Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1AE8-6136-E608-00000000F001}1608C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044785Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044784Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044783Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.443{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AE8-6136-E608-00000000F001}1608C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044782Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:04.445{323FE7D8-1AE8-6136-E608-00000000F001}1608C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044810Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AE9-6136-E808-00000000F001}4712C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044809Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044808Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044807Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044806Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044805Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AE9-6136-E808-00000000F001}4712C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044804Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.773{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AE9-6136-E808-00000000F001}4712C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044803Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.774{323FE7D8-1AE9-6136-E808-00000000F001}4712C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044802Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.710{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=081899AE3A0DECDE03C8199F191BFA79,SHA256=FB4BCF0D47032504F7B1CB8B0FC0BC195CFAF7BF963EC9A08C8309039C272C94,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025934Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025933Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AE9-6136-6006-00000000F101}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025932Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025931Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025930Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025929Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025928Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025927Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025926Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025925Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025924Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025923Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1AE9-6136-6006-00000000F101}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025922Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.746{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AE9-6136-6006-00000000F101}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025921Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.747{FFF7FB96-1AE9-6136-6006-00000000F101}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025920Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.262{FFF7FB96-1AE9-6136-5F06-00000000F101}26843696C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025919Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AE9-6136-5F06-00000000F101}2684C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025918Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025917Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025916Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025915Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025914Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025913Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025912Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025911Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025910Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025909Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1AE9-6136-5F06-00000000F101}2684C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025908Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.074{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AE9-6136-5F06-00000000F101}2684C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025907Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.075{FFF7FB96-1AE9-6136-5F06-00000000F101}2684C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044801Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.457{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=980C59E86B0C2C63987D23BA44EB40D6,SHA256=08E2EFFD26552B9E1F29FFC959580ED4C5F092A4142F3B472BDB8035EF468C33,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044800Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.457{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6DF67F6C87EE04447AC75A022ED53BBC,SHA256=85A330774B554698D4FB7DD2DF227060B976BBBEBB4D028F7E4116D73EB4B6BA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044799Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AE9-6136-E708-00000000F001}6228C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044798Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044797Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044796Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044795Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044794Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1AE9-6136-E708-00000000F001}6228C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044793Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.126{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AE9-6136-E708-00000000F001}6228C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044792Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.127{323FE7D8-1AE9-6136-E708-00000000F001}6228C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044813Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:06.726{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=45A843A1E8A5D7FAD0CF765ED36969F2,SHA256=9896D70C49A0FF1E9A69BFD2CED9903F943D0565D930AD3311999977233757B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025950Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.308{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=66A794FD0C11FFAC56B40D396C542E93,SHA256=EB39EC4B5CD0D159B40DA13CD6E407405BCD001CD0B59552CEA8B7C65CA54242,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025949Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.308{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FBD6341395C552CA91C328819BB26B9,SHA256=5B241B3853C21A43585608F8F4FAD8CE9431FC3D0080D050C00293A9C0139771,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025948Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.308{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=501BCE391F8D982BDF54CD35A9DD3D3D,SHA256=FF77D1C7D29DDAEEDAF30F36630B1B32F6BBE71F959A589A45A1805F26063211,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025947Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AEA-6136-6106-00000000F101}520C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025946Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025945Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025944Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025943Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025942Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025941Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025940Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025939Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025938Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025937Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1AEA-6136-6106-00000000F101}520C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025936Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.246{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AEA-6136-6106-00000000F101}520C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025935Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:06.247{FFF7FB96-1AEA-6136-6106-00000000F101}520C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000044812Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:03.689{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51668-false10.0.1.12-8000- 23542300x800000000000000044811Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:06.626{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=980C59E86B0C2C63987D23BA44EB40D6,SHA256=08E2EFFD26552B9E1F29FFC959580ED4C5F092A4142F3B472BDB8035EF468C33,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044819Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:07.726{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=290515E58C0544200304C175A9AA776D,SHA256=0D8C0BB4F17E7B40691A6D3569D0349ABEBB81F4EAFD21B28E8BA71E8796BF11,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025968Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.527{FFF7FB96-1AEB-6136-6206-00000000F101}400304C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025967Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AEB-6136-6206-00000000F101}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025966Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025965Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025964Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025963Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025962Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1AEB-6136-6206-00000000F101}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025961Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025960Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025959Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025958Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025957Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025956Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AEB-6136-6206-00000000F101}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025955Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.340{FFF7FB96-1AEB-6136-6206-00000000F101}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025954Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.293{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BBD56E29DA0C4AFC94F1D98E93FB8609,SHA256=8F044838E695E860FFBDE058B1B98CDA509A5EF56155ABAB21091B55C3B1BB0E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025953Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:07.293{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=66A794FD0C11FFAC56B40D396C542E93,SHA256=EB39EC4B5CD0D159B40DA13CD6E407405BCD001CD0B59552CEA8B7C65CA54242,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044818Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.196{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51669-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000044817Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:05.196{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51669-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 10341000x800000000000000044816Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:07.388{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-022E-6136-1500-00000000F001}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044815Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:07.388{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-022E-6136-1500-00000000F001}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044814Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:07.388{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-022E-6136-1500-00000000F001}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000025952Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.577{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50924-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000025951Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:05.046{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50923-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000044838Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.842{323FE7D8-1AEC-6136-EA08-00000000F001}19044172C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000044837Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.727{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D4834F7716784F735D0EB71199A47CC,SHA256=91E95C66B4C0765EDBC466131847BF8AA2DEE4C8FD24B1E0B219E6F67BD25B6C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000025998Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.746{FFF7FB96-1AEC-6136-6406-00000000F101}37642368C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025997Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AEC-6136-6406-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025996Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025995Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025994Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025993Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025992Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025991Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025990Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025989Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025988Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025987Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1AEC-6136-6406-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025986Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AEC-6136-6406-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025985Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.593{FFF7FB96-1AEC-6136-6406-00000000F101}3764C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000025984Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=93851CA3A3A034478CBDDD066A71CF33,SHA256=17A8C43BAA691E6CEC7A5756BA2C4C678D967984B2BFEC277D0774CF4B40B357,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025983Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.590{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4FE6D0146EBFD1CB6871F3D48C4007CA,SHA256=8DF47BB1AE1BA06EA042D6A300D61EA591768FE40C01AEB4B244D189982D9BC6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044836Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AEC-6136-EA08-00000000F001}1904C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044835Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044834Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044833Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044832Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044831Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1AEC-6136-EA08-00000000F001}1904C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044830Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.674{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AEC-6136-EA08-00000000F001}1904C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044829Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.675{323FE7D8-1AEC-6136-EA08-00000000F001}1904C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044828Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.227{323FE7D8-1AEC-6136-E908-00000000F001}4632944C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044827Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.009{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AEC-6136-E908-00000000F001}4632C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044826Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.007{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044825Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.007{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044824Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.007{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044823Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.006{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044822Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.006{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1AEC-6136-E908-00000000F001}4632C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044821Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.006{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AEC-6136-E908-00000000F001}4632C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044820Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.005{323FE7D8-1AEC-6136-E908-00000000F001}4632C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000025982Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.137{FFF7FB96-1AEC-6136-6306-00000000F101}37682520C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025981Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AEC-6136-6306-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025980Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025979Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025978Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025977Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025976Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025975Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025974Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025973Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025972Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000025971Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1AEC-6136-6306-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000025970Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AEC-6136-6306-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025969Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:08.012{FFF7FB96-1AEC-6136-6306-00000000F101}3768C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044849Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.758{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B9DE15E481A71DD9FAED4EE51FAD39E,SHA256=49DE929C35F7D9ECD4124EAA491C87A19954C436961F974A6789981146381BC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026013Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.730{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FB1E9761DD66F59406183297AA9DB572,SHA256=6FC089971661D2ED4F2FC7293E5D05861EBF7FDAE19DC205BB94A8C927594607,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026012Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.730{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C8513A036248549F0F5B12B1F7003D9,SHA256=65BF95F0BD4A4D5C80684F7CAA3B089C38E5730213640D637D8C4BB779607CCF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044848Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.511{323FE7D8-1AED-6136-EB08-00000000F001}49965872C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044847Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AED-6136-EB08-00000000F001}4996C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044846Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044845Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044844Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044843Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044842Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1AED-6136-EB08-00000000F001}4996C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044841Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.342{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AED-6136-EB08-00000000F001}4996C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044840Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.343{323FE7D8-1AED-6136-EB08-00000000F001}4996C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044839Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:09.009{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8C3F0DAFBEFD455DA61B297BD3485CBE,SHA256=DC34AB6CFD41D530B55327BB61CFB4AAFE6F3F437EF21BD5011BECBDDFC8F92B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026011Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1AED-6136-6506-00000000F101}2328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026010Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026009Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026008Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026007Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026006Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026005Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026004Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026003Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026002Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026001Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1AED-6136-6506-00000000F101}2328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026000Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1AED-6136-6506-00000000F101}2328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000025999Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:09.262{FFF7FB96-1AED-6136-6506-00000000F101}2328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044859Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.773{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=893E88A748A8E9A69CE89FEEFFA8B032,SHA256=AB7851C5C5216BDC1B24A3AD24780AA3F7C850B366032C16A440C765AC917CB4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026014Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:10.730{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2866EFD002F1D7BDFE31AFE6A8AC2AF,SHA256=04B2E702F05B546DF05B85BA6CDB97B2D2937E5631DBC0179342601050139520,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044858Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.357{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=46868AC0F0138BD18285FB54894A5BF8,SHA256=8CE4E075974240DEC582617E7595427591D2C16AC23784A27B037CB452942B7D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044857Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1AEE-6136-EC08-00000000F001}2876C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044856Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044855Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044854Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044853Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044852Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1AEE-6136-EC08-00000000F001}2876C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044851Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.026{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1AEE-6136-EC08-00000000F001}2876C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044850Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:10.027{323FE7D8-1AEE-6136-EC08-00000000F001}2876C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044861Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:11.787{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1548F830D5076F07F6AB94229025C38,SHA256=ACD6128F88737332657DF41B1924D9202B265A302921D521423A4590E230048A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026015Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:11.793{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6FE39EA626661CDB662711CC28BDC653,SHA256=63AEBE38E81882E6E187B3E2B02729DBAF71E7BB46F0C56D7C887CE0A93FDC0B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044860Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:08.781{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51670-false10.0.1.12-8000- 23542300x800000000000000026016Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:12.871{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6CF1B304F565802D94DA97A5673753E5,SHA256=C1A0C5D59B27753DD6C5438D992EFA26459136AB9FDAB90D7C742235D7F67F4D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044862Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:12.805{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FCB14CD0379FFF60A68636DE072AACAA,SHA256=D431C41D8A2F27D94BAE237DA728245B0A0A84DD5C36F1DD542FE95134478805,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044863Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:13.824{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1FBC3EDFD4BC85B1225CEABC4855D0B6,SHA256=8DDCFDB42A498353F77A806BB8C8A665F8CE1F586F4CBA90465FF2B763446FCA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026017Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:13.887{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D6A40CF0F2EE2094683C5B9739465AC,SHA256=DB3FA35006102A14E06DE939C42F4E996058899970007689D911660AD197028D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044864Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:14.839{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1076FEDFCF3EC84D3B92EA02CB3823D,SHA256=107401EC86D6127AACB06B0A6EA9C3FFE2A5240DD5CDFBEC052C64782D4202B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026019Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:14.887{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A3EA6777B1524F7F9405B3FC5B214A83,SHA256=9F3D1C242F265B8AD1AEA48E514549EFAE9F40966680B456AA5E969EDD101BB5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026018Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:11.030{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50925-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044865Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:15.869{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=992CC0FA394B2676FD0A1E988723B013,SHA256=1778D5A3E805E4D20B17A1D19A1572F2B821DAE13EEE9B6ED0C17547E36EED8E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026020Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:15.902{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA852EEEBBCC1F76513E88CC7E215E3B,SHA256=DDDAF3FCB73F12F6E9C1DA9BD20CBFD1BAF09F25D0BFDCB26A0F546D39C80164,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026021Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:16.918{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D80D72CA06DB5C2B5DA52A02C9155FD1,SHA256=A718133C6F708AABC5041FE6F8A8CA6DC29CCEC7F7EA4E3536CFC454D1F20A3C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044870Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.884{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2AF766070D8E443299FF95C8930EBCF3,SHA256=F9759FAD0D8958D44B782DC5E514C28440355D0774B68EA3401BEC242A3D1322,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044869Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:13.816{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51671-false10.0.1.12-8000- 13241300x800000000000000044868Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:43:16.637{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\9752B235-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_9752B235-0000-0000-0000-100000000000.XML 13241300x800000000000000044867Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:43:16.622{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\CED8D70C-FDB7-4280-B713-3A56B1B8A289\Config SourceDWORD (0x00000001) 13241300x800000000000000044866Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:43:16.622{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\CED8D70C-FDB7-4280-B713-3A56B1B8A289\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_CED8D70C-FDB7-4280-B713-3A56B1B8A289.XML 23542300x800000000000000044879Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:17.904{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A878A0E20A2150591A99BE28849A1AC,SHA256=56BC9754FE0D0F53A37B8B98D78765407351DB376920BA47CF99C00725B24F83,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026022Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:17.918{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9823A65A72D6A8FC22BD81AB9B33DFA4,SHA256=6FDC9AAA16CFAA83D21F8F3B7270F07C8C899C0738213432D7E7922E37ADA945,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044878Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.241{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51674-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044877Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.241{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51674-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044876Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.232{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51673-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044875Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.232{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51673-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local389ldap 354300x800000000000000044874Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.215{323FE7D8-022E-6136-0D00-00000000F001}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51672-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local135epmap 354300x800000000000000044873Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:16.215{323FE7D8-023F-6136-2B00-00000000F001}2976C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local51672-truefe80:0:0:0:2066:3a74:49be:6c1bwin-dc-456.attackrange.local135epmap 23542300x800000000000000044872Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:17.652{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=41FABD517B139F3A39C26722F1A5FCE8,SHA256=0C57B7A10714C6E22C7A5018150D7CEAA4E605353CBC2AB6CF0996F96670222A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044871Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:17.652{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=911B06E8D8B0EE1F987AE19AFD01D403,SHA256=7CFFE38109926B695A7955F9DB99C317D469D91CDAD815546D4A3F5B2B04726D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044880Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:18.936{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5A505062EAA044C146583B38DB8DC5DA,SHA256=2354768DAF5923BF18AD8D9E275AB236A9A32172E64B9731B46D22465282B61F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026025Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:16.920{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50926-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026024Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:18.929{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16FB675323610355EED83BB4C452A0AD,SHA256=F7A9396EE57BAE8130B784FD164C4D42BE01A0D00C47333859E5F2E5316480E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026023Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:18.562{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-094MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044881Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:19.951{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=075D594BEEE069E185F0D9C9545A4351,SHA256=D486904FF07CF3033A321A78E9F2F63891BE162E0644110EC92E9CA56710BC44,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026027Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:19.942{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9CDC43AC4DBA31A744AD5FC3AFEA6DF,SHA256=1D58A07B51BB9A66B523D58753CF743E26B8F037C802782154219A0049D2E81E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026026Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:19.570{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-095MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044882Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:20.966{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBACFC62C40ED802FB158E72DDA73E65,SHA256=F8E27516C93AFDE2632294E50C2FA34BAF3C97A059D3D1E54CCA184F3FE3334C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026029Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:20.944{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BBCCDA502F1A0E0505C0543C6EF17468,SHA256=D60A282EB1B0FAC8A207E1729C90F3B0343F8F9CA7CA51B7F31794C286320CCF,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000026028Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:43:20.929{FFF7FB96-041E-6136-1100-00000000F101}1008C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7a325-0x27e71e88) 23542300x800000000000000026030Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:21.945{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1BA77D2A0D09C3B97C07C1BAF6615F3,SHA256=861ACA52024C16AF660ACC5A8F827D3B43861EF19EDB4BFD72ED7194109B3447,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044883Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:19.727{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51675-false10.0.1.12-8000- 23542300x800000000000000026031Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:22.945{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=901F9B71A9AFCC88E1F6EA27EED2701D,SHA256=4F31D601F4432D69B4460FF6588C68254CCFBE13806AAF211E187FD8C68E2A6E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044884Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:22.034{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A3A3F4F58EB5E86C978670F1E34D6954,SHA256=B55C9D835E9B312899A7B4525C5168A0C8519DBE97E667E324D1886E07600970,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026032Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:23.960{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=99C7F58BB4BC70420E7DA8DC59E4AC9D,SHA256=4DAA1EA4052B1CCDECC7E78C5FD84AAD42BEEA6D5D609DF1510A15A22D6117BE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044886Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:23.049{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C6E56C26397B523D9918969FF36EFD68,SHA256=A649FF3737DA37014B05BBC2AD654356B0C551E16C6E355DB15BF6D79F06B530,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044885Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:23.018{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\permissions.sqlite-journalMD5=8E53D043E90010B39B355AC3F9871D6E,SHA256=70D36CB5A5BB2694CADA7DFC0EC653676E152D9D9C99929776B7BB0E87EE13B2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026034Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:24.960{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98ADD39EB5E262BE273274ADF03A726A,SHA256=9F1AE9290831480150C785C42BF84A8B601598EC8A9E47C94B6E5BA4C342E6B0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026033Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:21.963{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50927-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000044887Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:24.064{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=802891BF8DE06357F9C935C58F46E617,SHA256=2763DE6610684BD6F1E92FADADF769C3ED7B506A2D8CC6953F62C776E8380E1A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026035Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:25.976{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=653563514D127DA7A590E4CE63D34329,SHA256=0D2C9C388127817A83E231FE5F2F382CDE2E19485C48A26F5A4FCE3459D2441F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044888Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:25.147{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED26DA2F6B1CEDBBEAC7370D47FAA1D6,SHA256=ECC7997E15C0A103709BE9C8708FB8E075B814BA9079AA3CA02D6258720B3619,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026036Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:26.992{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A7CDC196E8CCBBFE8091203F6E318A9,SHA256=8A5BF4603FAC2586DD8B35343DC9ABFA8CBD5CD6C4EB8AB1E2870AC6AAB0DFE2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044890Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:24.755{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51676-false10.0.1.12-8000- 23542300x800000000000000044889Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:26.147{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1DAC145BEF98D843682398FA30B7FC0,SHA256=F95582D3A96F26E7C3D361140B6953FF458386E5F4358A1C436B7CB147D44E81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026037Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:27.991{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=531D51BDA8FCEDE6AE20C45E2B70AB51,SHA256=85BF4DF788A361BF08E43775870B3BA40B7D14748A37CA70F2D0B2FF10C31054,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044891Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:27.162{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A99CE04201BB78F961D88F40E343A5D5,SHA256=A3E5BE5C848556BDEF10C240DA9672BE2809B07B14E5FA61C0C9564B0A4A90B0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026038Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:28.991{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC3A1E4FA2091D8F1D4CD27855B81C42,SHA256=3D16EAB10F5CCCE4C287866F3DB98C3F5DE02C9D4051038009FC777BB4F7C554,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044892Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:28.195{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5CBC38B6BFA22528B61A9FB885892F79,SHA256=144355F9A65FCB331BAE88C3161E9E49B019D34D72CDFCFD865E255E5A9C216D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044893Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:29.214{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B793883D72358D5B247A3A642309FE4D,SHA256=3D90A7EEB824DD352054F3D36A54B20B6113B5768E313EB3581115D0A10F476C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044896Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:30.255{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044895Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:30.231{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-102MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044894Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:30.231{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=542A80E19B1B27B92AC08AB3195D0A69,SHA256=91889CC56A52979E924D9A0055FF274B6EB9C638A7F14BD5F52297F5C2B215FF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026040Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:26.978{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50928-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026039Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:30.007{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0FF3AAC659A40E02F85E22A9C7736EC9,SHA256=E086EFEE9DC9C8E6AA04168BDE0F9585A371A7FB0EC972EC49D12565266103E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044898Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:31.252{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2963E6612F1D05CEF5227FA4A3D62EFB,SHA256=0C4ACCD1057EC17B97348532DF0600F2BB42DE5A421CEE4B247C4995F631372B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026041Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:31.023{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B104DBC21B3D228B14395D57F4C00744,SHA256=4421260CB8DEBE51D7A4C7583219A67E9F6A3F7FA48503719BBC43D6A61770A5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044897Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:31.246{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-103MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044900Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:32.259{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C80935F8B8CD62290011CB9A83BC6DAA,SHA256=DF99194EE0CFD139CABC9E1AF9675CE29FE0FA9E0D05DC70487040BF11CEB97B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026042Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:32.023{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF6005F14B20BA2123FFD14053EF2B71,SHA256=2CD40267C2D420C224FDBBA6668A39ECBD3AA052035DAF2B414166737C6545C5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044899Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:29.831{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51677-false10.0.1.12-8089- 23542300x800000000000000026043Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:33.023{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C32CCAE6CB9F2ABD4FD5174735D4FCC,SHA256=390DE1CF09C21E1EB2FBB906CFEB2D6525C61F6EED1F9D351E401646F3AC6753,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044902Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:33.274{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=23F1FA1BF69DE17DF92DAAE940CA82C2,SHA256=B848987033C0F03CCB041A788EB8CBBE34A7541D53FF5D57D2A047F30C7B92B5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044901Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:30.784{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51678-false10.0.1.12-8000- 23542300x800000000000000044903Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:34.292{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F0C798A1C5796A684818D5BAB4A018B,SHA256=152249869F355AA1E464BFA7FC37C08007C370FF2BE0E760C31F114D076ABB03,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026045Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:31.978{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50929-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026044Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:34.023{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9A396C60C6CA571952D8540970A0FB1,SHA256=D3E67002F045B30A6C559CC47F54BF549ADF6BD8478EF31FC597E5D3D87AB588,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044904Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:35.312{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6A1116F295EBDF09B1FCE0A9D6C0663F,SHA256=9FF223A95697DF07988967A0D11A3D4DA51DA9294FA17D70B75CF1D8A0C3745C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026046Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:35.023{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=954E42C424D48608E88483BB080ACF5F,SHA256=C33E94F8B1291FD9159743985B9786B917FCC8C03D3D54CC33802CB8991EFF53,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044906Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:36.314{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BEC26871B750B9D76CD415CEBBAEEB58,SHA256=87D644C98FA61280EADC437D54177D18163CEF2EF932AC6DBEB0A0D495A6418E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026047Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:36.038{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53BB9E63E2BB0D0940A10F4999AA4455,SHA256=2AF53EA0AEF744EC90843DEB68D62365C668F43FE06D10DE52F69EF3AF46C73A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044905Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:36.243{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=6413591C385BEEE8888162330C08FEF3,SHA256=A760C337D6789358A77988AB980E9DEDB5E164C5E7CA59D21A27CC108E85C1D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026048Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:37.038{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F350DAB61EA3735B07BE72A4810D746D,SHA256=B832C76BF729C8F73ABD2DDCA5ABB1A0D0A04AFD0F62705C95664394BF118FD2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044907Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:37.314{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A2BD86F94279567C5E6F6768EDB445D8,SHA256=B005D6CA83D8CA3F918CBADCFCA7A7958BF290298A59E11A510069D1BE6DAC07,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044908Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:38.329{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=937BFAB6B0446B68256F9E1B4CB5A3FD,SHA256=2E6AC07A1A1103CD5CE5085E335A5D49ABF2F9A859E467C66A80B2C9297FB88C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026049Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:38.054{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=63E23A3DADD3A6F91223A44DE5D69D62,SHA256=B8C73CACFE19452B78ED76772BBFF9700374C8AC700703DA8BF246A0C05C649D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044910Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:39.360{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0234773E5BB5BBF91AF88E781D3CFD1,SHA256=BCB73466DE99CA77942D312AFCB13FF28BA4B49EE301AFD637BC6F170E70235F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026051Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:37.900{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50930-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026050Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:39.069{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E36B6B0E9919CF0C796779A5FCA3F2B3,SHA256=97FFB153BD136536E2085BC1E97EA63C71A74E8EBCF2A2610F5DB4F597AF7583,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044909Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:36.684{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51679-false10.0.1.12-8000- 23542300x800000000000000044911Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:40.392{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC4DBDAA9D5F326A61FFFBAF38F8D147,SHA256=32289E6C723B0BFC25F5DBB34857EAA31104D8206E7ED1757AB09F47D8E384D8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026052Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:40.084{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8AE67A3489079B1BDEF45F7BED2C915,SHA256=F3003C2BA4513A00FA2647F1A176E1E5DA59AEEE16BB4FB1FDB7FB543FFF6D36,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044912Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:41.404{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E15839BD8D69B418B2357E3D333720EF,SHA256=F8D0BB0B2E5375D42BC098EDC64AB69E0C69FA65853F787BD88D3C3E737199F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026053Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:41.084{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5E66C8A4475F4009F43D47729AD573C,SHA256=A740D4E84FF94DB50BB478D92489D45F57E1C51DA6B25C55E6D95313FA6514DB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044913Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:42.424{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1DE4350DA16E5026C2E378E9E9A28A51,SHA256=23309F8C84DB6E7037139A778AC6884C667F954FABF203024F377917939916BF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026054Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:42.100{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24611B9A99DBB7D6C6105254FCCE53E5,SHA256=4F9508A2D99A14B4DB866D2A8F31438650E1580613DEBD89F6B284D9498DE091,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044914Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:43.439{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A7F2E8AB7F76CBE1E2EA1C423018C3B,SHA256=1CE7756E1E57796552AEC2E09D6D2444210DB89BDE3BC61A774DEB35F5D5ABDB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026055Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:43.104{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=52152826300A4D853EEE52B623121A5F,SHA256=2EE4F3B5B24BB98C9B9A82F7EC414EEA27B9FCD791D1385949B1643A7E9338DA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044916Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:41.832{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51680-false10.0.1.12-8000- 23542300x800000000000000044915Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:44.470{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=762F619F3C69A6622401BAC41835F63A,SHA256=4C4799EFC2A08FBDF66985472FAB782637C4203AFA633E41B68D69E5E182388D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026057Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:43.087{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50931-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026056Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:44.116{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7F69461E95D9A36B575ADDDEDC8DE9A3,SHA256=9F3B463591F128A78FC4AB655ED14A50E1D48A493E396C422EB08669EC155B05,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044917Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:45.503{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1398B1D3EC8F4436B34EF3503B966F1E,SHA256=44D0FA5EB675A0A79F7A97EDDDAC687A8D4A80146C0644AD29AA9651A032A9CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026058Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:45.131{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A3D8726805A52EE36119CFA20DEF6F0,SHA256=C40035B236D7FF36541CA55AF72CEB776B5F85A4BB308F877BA08EE299B40F8A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044918Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:46.537{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3AE24A0DACA7AD8FE74AB89164C1CF73,SHA256=5BB6D291143F02009991345359B0B9419AA0A7496C4A21C65D83E0A38D8DBE9C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026059Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:46.147{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3539D781E0C3491F769AA59FDCA60AEA,SHA256=3D469E2CFD87A1BE14958BA6FC0DB1DF3110FDABE673562FEC9CBAD7097C6EFE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044919Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:47.568{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=979106FC39B0E15219CF273555847459,SHA256=0D322642C69C9FA100207508FA0BFF559D41724C83E3B6E6C4928A8A6BF3A87C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026060Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:47.147{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD5164D7577C3B4DD4654B77FCD825EF,SHA256=19B29285E2A209C0A7BC15986F86D8F93C34CD77BA54AB818740C6960A24AF58,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044921Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:46.844{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51681-false10.0.1.12-8000- 23542300x800000000000000044920Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:48.601{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F6B356C7B75B666E9121800D483FF30F,SHA256=935165B389E12D974E35A95AAEA1AFA36BCC2CD0F6735B9C2116FF579291AD8F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026061Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:48.163{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=579079A1B72996E5CD3E03F94B36C6C3,SHA256=E96D0A47BB0E056EEDF52437A5C628DC0529BAB7C58C37A1D2D76CCCF4114158,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044922Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:49.635{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9F378DA3E0AD166AD8B1FF1DC65D9A9,SHA256=C09FBD426306D8262C35DA2EF6757F69AF4F32F4012484783E4C0DB0DF9B89CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026062Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:49.178{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FEC910D9EFB0A9664A438BA9BB033F68,SHA256=C2F0F58BA9E631355BBAFA25B99ADD822EE8901F6DE4878B6740F7F1A1982615,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044923Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:50.666{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=916EDBAAE63D20E56D84F7FA136E3056,SHA256=C1C8B317D30373701BA393311D63EEC3BC3442F0BF2BBC7EE94714376479621B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026064Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:48.853{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50932-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026063Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:50.178{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27CB128B3907BB0F410E5211E80AD3B6,SHA256=95A7D578D6D6596D4F9D28A8E4CEAD7768EE71201FF74F6A6844371728F6C12C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044924Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:51.699{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=59769B9C503C1BA588BB07AD669C5BBA,SHA256=C6BA2453833BB5F4A5BDF69BBE5EF8BA47BB1C93B1A91ADEA111D19D230F5D44,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026066Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:51.616{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=AC469CBEEA4EF790C375A6F12086811B,SHA256=B0CB5FC632E2760CADC74F0985F163101632ABD0190E2811FD88B9553226B2D8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026065Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:51.194{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=86C629CE7A22E0630E1B123C03553FFA,SHA256=57AC887DFE8A5CCE89E4B98F0CA9D60D8F7FDCFD4DD8DBBB9FD90585958F733D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044925Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:52.718{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F13D53DBF067E8B045CA1A03EF6E5702,SHA256=446A25974728D64B0E71B992A9B1CC443250A1446AA9C22EF48BDA3E7271B9F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026067Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:52.194{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A765493C1D9D66425DBB49E92142DD78,SHA256=DF25D371C548D32A3E7FF62EDE17114E9896B0989B36DA8F0E65E550E31ECD02,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044926Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:53.732{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D9E9C2E7C0F7A057F31917387BE4BB8,SHA256=635E63CB501768D47A110B172DCA8BA3D91D8560F1B6C8652E4877BC81E4DCCA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026068Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:53.194{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=490B265B9601CE34A626F60AD0450D23,SHA256=F760DBB17E7C88C85090327731FDCCB3D903D1498A5108037D66F5DD6E63006D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044927Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:54.747{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=780684A806EC906F0A77ECEF785DFE93,SHA256=B5AF20F47E4F0D80A5BE5B8631AFB814A9DCF1F1A490E8644AA328B841A91148,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026069Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:54.194{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EFE7DC3BE9F1FBC017FF9C3AA609AD08,SHA256=977191DB599C851CE23B433F1FE216311778B1A571ADD3BB8AA092797EB02A74,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044929Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:55.763{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8692329D95E2FAA0E0C6B1122954E9F4,SHA256=3B21D12301B6347B9798DB5513F88758E42B8855B125EC2A48C2C03D06BBBCBB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026071Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:53.915{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50933-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026070Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:55.194{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6D01437B312872A359049C1FE432FEEF,SHA256=CA4DB84FA41A5B519CB707F2B7020ADBFEC3922561EAC18399CA513E1C1BED7A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044928Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:52.756{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51682-false10.0.1.12-8000- 23542300x800000000000000044930Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:56.778{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B69D058CED8908F178C95286BEE35877,SHA256=9F42211451A50E62754233B2AEF003C6C3D8A11B47ECBE7F95C5F717A1ECEC76,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026072Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:56.209{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3A6C891E4EEF539C8F79128318BBC943,SHA256=4E9B8168C4F89DB825971C5D8B01C8E0670F43B3208E972155A6E7FBEFF76A34,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044931Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:57.795{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=459C30B9827B7B638322BA76C8DED4DF,SHA256=B434C1950B6784583BCEF58AE2890DB23EF47BFA233ECE531089DD44BAB8F312,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026073Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:57.225{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C1112C65ABE5DFB10FC55D6C0741B9C,SHA256=286924CF6285A6339E3DECB98B0E7986AD9F0F635D51413AF1AA4D107B7D03BC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044932Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:58.831{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B0AEC6E06392983AB430BC4D636442A,SHA256=950ECECEB283ABF71EE702569620B29B82C7B7EFC2D08A93FC3669B85083C826,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026074Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:58.225{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=311707D18C804A656EB263921F6F0FB5,SHA256=70A3C5BD1EA2687147F3D9DB1BE4BFAD9E01C51D0A11B9193A53A1462B95892B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000044934Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:57.839{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51683-false10.0.1.12-8000- 23542300x800000000000000044933Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:43:59.846{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E12E805A8E651087D7B0A3625F503E27,SHA256=C8FF16226CC9341906D5725F7263FC6676024FA465FB5AB4C5ED3BB3B3755DEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026075Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:59.229{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD66F5D95A7F8CA6F2D5C59D18D32323,SHA256=B62AB93BBA6BCB0050C0B71A4F8A108B1BC25C9FFDC1E72CE1351FB99262B88E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026076Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:00.229{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03A1DBB8ED65AC9BAC64EDEDD11A96D1,SHA256=158F843706F1F562C946EA65D02FAAB91DFBCF8C2757A2D51BBC1F2B9CD3D494,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044971Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044970Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044969Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0549-6136-8002-00000000F001}5500C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044968Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044967Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044966Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044965Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044964Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044963Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044962Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044961Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044960Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044959Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-0547-6136-7E02-00000000F001}5276C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044958Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044957Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044956Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044955Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044954Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044953Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044952Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044951Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044950Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044949Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044948Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044947Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044946Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044945Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044944Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044943Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044942Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044941Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044940Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044939Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044938Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044937Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044936Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+d34e|c:\windows\system32\rpcss.dll+c38a|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044935Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:00.730{323FE7D8-022E-6136-0D00-00000000F001}904924C:\Windows\system32\svchost.exe{323FE7D8-053B-6136-6E02-00000000F001}4440C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+f681|c:\windows\system32\rpcss.dll+c264|c:\windows\system32\rpcss.dll+d73e|c:\windows\system32\rpcss.dll+a35b|c:\windows\system32\rpcss.dll+436a1|c:\windows\system32\rpcss.dll+437d2|c:\windows\system32\rpcss.dll+43b0f|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000026078Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:01.229{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=882D9F290359D026E6129AFACFCE2BBF,SHA256=54C7EB4874E1F3E85E91C603B5E04CDD2EB718C0D53DDAF973D1930644CF5DC8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044972Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:01.130{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C4525643E8A6498AB67E0D2E1BEE7B84,SHA256=4BBFABFB8220206FB2A12AED0E95B4C5B5614BA4743CBF265778BD9532276A27,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026077Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:43:59.091{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50934-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026079Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:02.245{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F299C5490521DA0F04976591B355241,SHA256=84D45BA221E2896F21AA8F12A457DEC1E8A1E3F8100174D6ED5240F01B636859,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044973Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:02.160{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3C1A5FD4DD3E37BC9E9F509704C58D5,SHA256=FB4EC1230A25AD11BA314AAC415433E7621D522C8FED11A15AF2F5C46E632D3C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026080Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:03.260{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=504B0691A3DB5D58F3C21D7AA8022993,SHA256=5496C04033A1220724EC9F4D58313A5EA23D42FF1A8C0300F66F6087BC32EAA3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044974Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:03.175{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB11D391D54FB2F42A38B3DE23E00DE2,SHA256=4639C33611DF3F8D6AA834911FA1A1F3D8783D078C4807AFBC81E92B7A93C61A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026081Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:04.260{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2565F3779A204959AFABE42E8107CFA7,SHA256=6E8E745422E60716FBB26AB8B31CEA7CC81695E625A82F5C57DC2159CB94DA61,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000044983Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B24-6136-ED08-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044982Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044981Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044980Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044979Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044978Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1B24-6136-ED08-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044977Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.460{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B24-6136-ED08-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044976Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.461{323FE7D8-1B24-6136-ED08-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044975Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:04.176{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=61F9980CD529D68E515FE1F7660DCE70,SHA256=A5048F4C0563FF9DF52691D21908E092DACF43D5A1EC06E062913356FAA17950,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045004Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.995{323FE7D8-1B25-6136-EF08-00000000F001}65282460C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000045003Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:03.736{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51684-false10.0.1.12-8000- 10341000x800000000000000045002Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B25-6136-EF08-00000000F001}6528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045001Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045000Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044999Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044998Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044997Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1B25-6136-EF08-00000000F001}6528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044996Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.813{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B25-6136-EF08-00000000F001}6528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044995Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.814{323FE7D8-1B25-6136-EF08-00000000F001}6528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000044994Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.460{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B96998F7FBFF6518501D07EC0CA73CAC,SHA256=383EAA224D564ADFD8435EBC2121C822628C77AB57B093E3944155FAEFB61640,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044993Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.460{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=41FABD517B139F3A39C26722F1A5FCE8,SHA256=0C57B7A10714C6E22C7A5018150D7CEAA4E605353CBC2AB6CF0996F96670222A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000044992Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.176{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64B55AFA8C118467DC5BD677E3D2C444,SHA256=C1AC879640A5C12102B9410156E425ABE068983E9CC445C0D21A8BF54EA77279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026110Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.776{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026109Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B25-6136-6706-00000000F101}2984C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026108Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026107Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026106Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026105Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026104Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026103Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026102Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026101Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026100Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026099Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1B25-6136-6706-00000000F101}2984C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026098Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.713{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B25-6136-6706-00000000F101}2984C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026097Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.715{FFF7FB96-1B25-6136-6706-00000000F101}2984C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026096Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.276{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F491C01EEA3D918FDEDE01EC7AFC651C,SHA256=FAA0955FAD36CB85463E495938590070AC42010BFF7FA7B132AA10350D19FE5B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026095Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.245{FFF7FB96-1B25-6136-6606-00000000F101}9843980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026094Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B25-6136-6606-00000000F101}984C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026093Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026092Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026091Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026090Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026089Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026088Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026087Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026086Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026085Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026084Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B25-6136-6606-00000000F101}984C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026083Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B25-6136-6606-00000000F101}984C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026082Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.073{FFF7FB96-1B25-6136-6606-00000000F101}984C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000044991Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B25-6136-EE08-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044990Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044989Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044988Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044987Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000044986Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1B25-6136-EE08-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000044985Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.144{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B25-6136-EE08-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000044984Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.145{323FE7D8-1B25-6136-EE08-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000026126Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B26-6136-6806-00000000F101}3176C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026125Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026124Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026123Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026122Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026121Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026120Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026119Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026118Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026117Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026116Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B26-6136-6806-00000000F101}3176C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026115Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.338{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B26-6136-6806-00000000F101}3176C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026114Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.340{FFF7FB96-1B26-6136-6806-00000000F101}3176C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026113Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.276{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2B03E675D6757587F539258650DCB71,SHA256=45F2077770C158C0C057BA357A63E1204700B477E14816FDD0F38A710C924EE9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045008Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.205{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51685-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000045007Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:05.205{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51685-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 23542300x800000000000000045006Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:06.659{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B96998F7FBFF6518501D07EC0CA73CAC,SHA256=383EAA224D564ADFD8435EBC2121C822628C77AB57B093E3944155FAEFB61640,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045005Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:06.213{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=502E3D5A5BF20490CEA84993E762A97C,SHA256=DC0DCBF9AAA0D4AC2484B8912CDBD07EAB93F0CB363FECCAE46EC1D510EF0EB7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026112Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.260{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=54E2F893ADB31B5A82B3F836439A666C,SHA256=6785F3B2D1776350E3588A68FB3D9921F0B8795B247570F2CB53858FFE49487C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026111Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:06.260{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FFF0F8434AD9E1EF0E7056E5B82DF0C5,SHA256=BD20DDA494FFE47D9816C36779015C05905C2EB7801D9AC1783992A4ABC6BC54,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026144Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.526{FFF7FB96-1B27-6136-6906-00000000F101}28643412C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000026143Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.370{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=54E2F893ADB31B5A82B3F836439A666C,SHA256=6785F3B2D1776350E3588A68FB3D9921F0B8795B247570F2CB53858FFE49487C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026142Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B27-6136-6906-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026141Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026140Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026139Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026138Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026137Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026136Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026135Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026134Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026133Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026132Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1B27-6136-6906-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026131Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.338{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B27-6136-6906-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026130Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.339{FFF7FB96-1B27-6136-6906-00000000F101}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026129Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:07.292{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC184DA5B8F026EAFCE9683351B92F30,SHA256=7BBC87B24A2ED45B3F5D5B22AB1533AFA5DFD7B4993BF43D2280075AFC6B411D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045009Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:07.228{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF5969C317832FD7B0248AF4EF1FF961,SHA256=CB6B91F934E534CD7FD2335C8BBF608FEEBCB1129DCD3470788B303CA44111B7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026128Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:05.607{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50936-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000026127Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:04.935{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50935-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000026172Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B28-6136-6B06-00000000F101}3676C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026171Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026170Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026169Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026168Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026167Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026166Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026165Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026164Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026163Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026162Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B28-6136-6B06-00000000F101}3676C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026161Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B28-6136-6B06-00000000F101}3676C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026160Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.622{FFF7FB96-1B28-6136-6B06-00000000F101}3676C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026159Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.620{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=860887F97E3D03E3009442FD36D6B4F0,SHA256=B5B95016B3A67C2817D865BE37D850918A2079918F8873BE716722D94F97BFA6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045028Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.697{323FE7D8-1B28-6136-F108-00000000F001}58405808C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045027Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B28-6136-F108-00000000F001}5840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045026Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045025Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045024Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045023Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045022Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1B28-6136-F108-00000000F001}5840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045021Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.513{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B28-6136-F108-00000000F001}5840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045020Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.514{323FE7D8-1B28-6136-F108-00000000F001}5840C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000045019Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.245{323FE7D8-1B28-6136-F008-00000000F001}44201960C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000045018Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.229{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C333769FC0907187E4135282F240C77,SHA256=4168199FD47C2B5253BC017FDEB8436863BBB627D9FAED6FC549E6CFDD8D7C4D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026158Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.182{FFF7FB96-1B28-6136-6A06-00000000F101}28722492C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026157Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B28-6136-6A06-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026156Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026155Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026154Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026153Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026152Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026151Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026150Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026149Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026148Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026147Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1B28-6136-6A06-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026146Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.010{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B28-6136-6A06-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026145Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:08.011{FFF7FB96-1B28-6136-6A06-00000000F101}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000045017Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B28-6136-F008-00000000F001}4420C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045016Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045015Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045014Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045013Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045012Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1B28-6136-F008-00000000F001}4420C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045011Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B28-6136-F008-00000000F001}4420C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045010Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.012{323FE7D8-1B28-6136-F008-00000000F001}4420C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026188Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.760{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=25517A0A83DCE8BC2443DB52B3F1CDDF,SHA256=E477DFAB0B1B52BE654DEE00530D14562EBBD51B9B5F7CDD3BEC943068901FE1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045047Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.796{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B29-6136-F308-00000000F001}4152C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045046Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.794{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045045Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.794{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045044Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.793{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045043Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.793{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045042Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.793{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1B29-6136-F308-00000000F001}4152C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045041Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.793{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B29-6136-F308-00000000F001}4152C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045040Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.792{323FE7D8-1B29-6136-F308-00000000F001}4152C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000045039Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.298{323FE7D8-1B29-6136-F208-00000000F001}34846584C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000045038Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.260{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D0BB2C0B3F1608825C7067DA210056C,SHA256=AC9645CCE5222FFDF1C292A80ABEB86B06A9DC2524552BEC93DB5001BFDFCE89,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026187Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.432{FFF7FB96-1B29-6136-6C06-00000000F101}912840C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026186Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B29-6136-6C06-00000000F101}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026185Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026184Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026183Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026182Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026181Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026180Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026179Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026178Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026177Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026176Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B29-6136-6C06-00000000F101}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026175Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B29-6136-6C06-00000000F101}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026174Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.292{FFF7FB96-1B29-6136-6C06-00000000F101}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026173Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:09.245{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=25193BBFE0EA5164722F1EC3E457295B,SHA256=F87E127D690EA52F49524FBE0364388C481A0C3B1A12F6218F271CEC59ED9F0F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045037Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B29-6136-F208-00000000F001}3484C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045036Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045035Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045034Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045033Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045032Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1B29-6136-F208-00000000F001}3484C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045031Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.129{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B29-6136-F208-00000000F001}3484C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045030Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.130{323FE7D8-1B29-6136-F208-00000000F001}3484C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000045029Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:09.013{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DEDAC81FA1EE8EA861F28B503E6EA4E1,SHA256=576570ED4A66E928D6543B0E031C64F4805BB6A79D2AE8270A8245D510FD7F27,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026191Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:10.807{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DF843FED94F3975E1207983EAF7871D,SHA256=0246DC7DC846C743E05E10510DBE6DF0C8BECE82F414780A6BDE3D3B920567D2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045050Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:08.768{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51686-false10.0.1.12-8000- 23542300x800000000000000045049Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:10.264{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC0A8438C6EA62F2B4B5127E6102F21C,SHA256=4F420A0390300422F2E134D499715F18B22C9A4A183B38F275B4E867E63EB91E,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000026190Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:10.776{FFF7FB96-041E-6136-1100-00000000F101}1008C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7a325-0x459d2e65) 23542300x800000000000000026189Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:10.307{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D6362DD7EE2351A3E61C677B9E4D7242,SHA256=1DA962D3BC5B9A62C17E006AC2867E385C3E8861BA83D3CC414A619D48CFA277,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045048Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:10.133{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E456495E9B5A8E93F01927E4CC7CF029,SHA256=3747C76A697FC686504CE72DA832D8DA992E58649946CDAA6C948573EE298C94,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026192Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:11.885{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36CD31BFB3E0BD2FC30C58DE90DC2F30,SHA256=0637880AA349CC7340E72228CBFF62404CC4330CBF488FD5D62A140E30BD8FBA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045051Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:11.299{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=81B5AFFC0888824EC827E600D514C01C,SHA256=80FA7A3A9AAEAECE6A3F330C4AE141D51F5A24305C133148713F470128381341,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026196Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:12.917{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C6B937EC156242C2F57014894435652B,SHA256=B67709C0C65FA30506DA6B1E2F6E2B72AB8EC6586A1425A6E6D54CC79F1FA2ED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045053Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:12.316{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B940057EDDC7AAB5BE4AEB76346CABEA,SHA256=FC25ADA14C573F1A9FC0A9CA67D0B9C25E71E5748E2AF636EC4CE3BD2CAFA415,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026195Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:10.919{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50937-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000026194Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:10.606{FFF7FB96-041E-6136-1100-00000000F101}1008C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.15win-host-353.attackrange.local123ntpfalse20.101.57.9-123ntp 354300x800000000000000026193Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:10.606{FFF7FB96-041E-6136-1100-00000000F101}1008C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.15win-host-353.attackrange.local123ntpfalse10.0.1.14-123ntp 23542300x800000000000000045052Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:12.079{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\permissions.sqlite-journalMD5=CBABE87EC8DC2FA5CC5EE15F47FBBE6F,SHA256=4669D34B2DAB23875BC89194B6D2A23EB5BB04B344B7BCCA60AEC852F8D87746,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026197Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:13.948{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6A693E5E6CC8663D6B605D6A2310A183,SHA256=7ED9C04D65206038A8B88CFB9327A606DF187EF33FCF63833C15002E2D9C1AA1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045055Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:13.317{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1EEEE447E335F7977EA1E3B882519277,SHA256=5432D03E16D58AC181300364E73637756B6C20CE089E387060B426E9A5A8A58F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045054Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:10.383{323FE7D8-022E-6136-1100-00000000F001}492C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudpfalsefalse10.0.1.14win-dc-456.attackrange.local123ntpfalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal123ntp 23542300x800000000000000026198Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:14.948{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF0D45FD26528A92DFE2B5EECEEBABEC,SHA256=68FFB0BE774031FB109F9BE4D5E82E429CC2E03CE0B21441F31BDE0C636CA026,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045056Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:14.348{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=175C5A2CDC54550E3B64B33C2AD1C6A3,SHA256=E5D1510EFDF37112E9D6FED48056EA1DC4A9A81D8A6293715961F53A29CD4CFC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026199Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:15.963{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=62687C7ED2D5CA93C231B95A7CE77F83,SHA256=BBC081A177E7326AC6FA6175FD1165BA85DD85F091E79A827850972986F0107C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045057Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:15.378{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C5CB684D0C5717559B0053E2A00756C,SHA256=D56CAF606EF701AD6FC2AB03940A3A30A703B9C0C8EFB8A8A6722D4D8F5D0AF0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026200Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:16.995{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=773D2A8A279AE5B93C6875290DF07BA5,SHA256=40155C7988CA074A6C567A67A0AC25B31708EAE88C88BE8029447199B1024653,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045058Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:16.396{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=018B8737A6A1B5CFF0D7ED1CEA4A6A94,SHA256=A4F77D79CA6E1FB5031B7ABD39F83AD11D5C2AEFC7ECA11682B81A146C784366,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026202Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:17.995{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B9D092A1F10EEB1CBE10A22546DECA10,SHA256=F9F3D2634D5CAD2CE48BAE68352A2ED3B26225FAA1BB4D564367F4AE24ADDC32,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045060Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:17.415{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C0AF8A593E16A9A1517E2E745898D64D,SHA256=45544C578B8F29EDCDEA89D6E20DEC4B08C5293C94774030B78DC55241AA09F6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026201Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:15.950{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50938-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000045059Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:14.639{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51687-false10.0.1.12-8000- 23542300x800000000000000045061Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:18.430{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=995D33DE3D7FDF5A0574048F3289B7BA,SHA256=B15690E68DE6786A4A819B61450007B2CAAFA88205DD820C01487F84A47A3432,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045062Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:19.445{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D28DC87EAA901A7DCEDECE86F3C2A9A4,SHA256=D25A554CFD2D3690FBB1BD3F17D7CF885886DF0E2CD45D2B70A0F532E6F64E9B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026203Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:19.009{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9C88EF02BF660CC308DE031F5E79C214,SHA256=282F340514F75B54C3A5F0F624EBBC2E8B1F6A4ED6E3F4440CFFDB7622287646,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045063Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:20.475{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A04E325022787E3B89B2C11D61431E33,SHA256=362299792E6C3D7DDB2A424690D5C7832E78E4670D4687D5426F845CDE4DE8EF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026205Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:20.091{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\respondent-20210906120554-095MD5=4761C661187147E55C9BD88F93ACDD3F,SHA256=E49051AD655512C416AEEFA39D6145E31F50204E8459201070596158B48A8487,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026204Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:20.042{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC01619209611FB89C6FF8EE6EDF0AAB,SHA256=73AA055D46CFFC1BCE66656BD2621228F6FBEECFB05402629F8F3A14184CED69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045064Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:21.512{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=94E8DCEB1B51A32F9EC1F4338D8FDBE1,SHA256=DE6CF9445A327F44F019949A71113B09519A7AEF6D11359C72116A0A74EADEC0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026207Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:21.096{FFF7FB96-041F-6136-1A00-00000000F101}1896NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0b9bcd2584272427e\channels\health\surveyor-20210906120551-096MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026206Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:21.079{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=33E5488E4E0E4B1E4FFCF3C66197AFFF,SHA256=D545F2DF9C7099B5174D79B1EB92BE8A467CB0CF9DFE7CF34C300EC102345E0B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045066Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:22.527{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C98C556546A822DF0A8C8EC9F6202AC,SHA256=D323EA3379023AA20AB4C6989AF2B6436571B23C5AA27DC1BFDBBC01C5ECAEFE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026209Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:21.049{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50939-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026208Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:22.095{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E09E7776D3FD5FE6D57BB327066E7032,SHA256=6179655756015630B9CCC2B70149C4B60AADA2A361DBC29B28113DA3F52E9D73,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045065Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:19.820{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51688-false10.0.1.12-8000- 23542300x800000000000000045067Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:23.542{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EFAD4FA040672FFD6C39C56D69FAD587,SHA256=E8307A0FE08742042B08509DE5D9B50FF9E89369BDC755709EF3140A88DF2363,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026210Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:23.095{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B454656C7F165090277A50B49F05289,SHA256=E5C1B91C19D798952B94C60EC62E9EEAB00066C136F9241659A8041E451D2A69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045068Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:24.610{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6CF912DB50B6F00AEC9222B010DC5702,SHA256=463DF1B368D7AE842BA7984A9FF67BA9617FF1AF13611CDFF7466DFFC590956E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026211Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:24.111{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5CB13491BEFAB0ADF6899DF731A39F5,SHA256=F62B8BFE954797FB757B2190FC72C9AE99F26BDBB8F2F461D4F7718014812E34,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045069Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:25.625{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=10A84A923E7711B47EDEBBFD00C15880,SHA256=45807DDA1914682741BF69A4BD1AB930AA53AEB847BEA62FA2F605FB5294BCF0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026212Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:25.127{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC53153BD88B2E9384EE772139F091A3,SHA256=E0ABEAB5EB6537D7868CFCCB7ED5B46ACC9B0F526CA0720EF11981D4F686309E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045070Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:26.640{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=86A85ED0897B740C399748F9FE77C228,SHA256=6330837FD68AE3BEB69F9680E933F7A33A233FB068746AC81A615EF92661A4CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026213Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:26.127{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3B05E97E41FA078B065C6A1B86F9533,SHA256=83D782CFD324E740239A89A746904C40FFB8C33D7308D6D17099255BB19E9D74,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045072Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:27.655{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21C928605CA9B689BEEE7368108C9BBD,SHA256=91E4BAED74587CD49607314DE40E5E3917ACF3E43A3D127476C0418595D59717,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026214Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:27.158{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C07DAD8EB49A7DB64454F6610AEBF299,SHA256=7E9186AFE8357436B725701B609D307B95058938A73EE6936ED4B8EEB367F370,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045071Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:25.632{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51689-false10.0.1.12-8000- 23542300x800000000000000045073Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:28.670{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5091F4BA293963FA841A85513197622A,SHA256=26F03718B7FD96B02135FD3E155FB2A54BBBB52B20B29FB89E5A914533AE9F2B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026215Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:28.158{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F8DE664F3A6AC3AEFCE8DFEA3381C28B,SHA256=58B5CD868E7F5B1360A26E8575E8B8BB32A5460DBFB68E179211E2390442F639,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045074Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:29.687{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D129F3A6EACA2BEA0F0583D4889B58B,SHA256=54F67326D39084282C36CFC9EFF8EAC28F680035BD93484A35A5F8F1058F061A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026217Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:26.895{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50940-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026216Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:29.174{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A408A35A5338223BC130BE83D1165928,SHA256=29FBC43982D12EAC9C12648EEFE406A4B641A5000BB4B7A86998A8B7C1637A86,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045076Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:30.706{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=368BD34B8EEE38A940126FA80858E901,SHA256=4280D71DE0ECEDAB8C1B9B05BB0271787A454DC7205B5481893D5CA83F5384E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026218Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:30.174{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A4A743687CBA80D92856DAF84FFD62A,SHA256=F7F2585396E04D847ADF3C60F65D4A8B024013DDE75551403A71A95E649ED4E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045075Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:30.290{323FE7D8-02BC-6136-A700-00000000F001}1036NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045081Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:31.991{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045080Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:31.991{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmMD5=CFE38EF4D0E3BC77F1DA07D7B5AB2A4A,SHA256=5F1944CEB72658831D8BBF81ADE689DD43E33B47384CCA94E8BA0DCA6F691D04,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045079Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:31.770{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\respondent-20210906115753-103MD5=58D52BFFD80488B8005F7C319C2D4334,SHA256=B9D8441D1BC2ED8425146F5F211E2A21C477807F4E0B7EBAD9811C868FAB9279,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045078Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:31.721{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C7BD1408BD63A571CA2B83F3CA99D80E,SHA256=5B2A8B7DD8C2770A5CCD5A2B6E76ADAAE50A0FFFB01F803B7D3ED6166328BDE5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026219Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:31.220{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=137522989970D5257758DA8CC5758836,SHA256=8788B6D4359B30D130AF34FE275F93405B6365E6FC28E140396731C05A245961,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045077Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:29.860{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51690-false10.0.1.12-8089- 23542300x800000000000000045083Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:32.770{323FE7D8-023F-6136-2900-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0fa896e07c0bdc047\channels\health\surveyor-20210906115751-104MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045082Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:32.738{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E024DC0EFAEBCE91A033A9D019D5163,SHA256=4DD225B46B14D9BE486EA33C3B65968C18423F4CCA95F903AC46EBC2DB8EAA6C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026220Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:32.236{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09A73DF44139350DE345FA7AAA5E045C,SHA256=8F5057E576C32401FDC70B723F37F080DAFDE99786C171A1B31F37C20500421A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045085Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:33.753{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97FC520516D3F57EB6D8AFDF4BEA3B2F,SHA256=1BDD855D76C4FADB2921D0B5506CE461A651DC4203477B8DA2599CC79F10AB62,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026221Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:33.236{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F83FD1CDF27EF98DA33BDA1F4C3B9F56,SHA256=D33A2BAEE8D8EC8D05BFDE18524720C3E967CAD647F074B84E71B0C04909280B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045084Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:30.828{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51691-false10.0.1.12-8000- 23542300x800000000000000045086Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:34.768{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5AD98EDB684BBD4F650F07994EA7DD0D,SHA256=678A1EBCC188981C7F8A6C18DE98DAAEF5275C0BA708598AC28291145DEE0385,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026223Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:34.267{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D5863E326ABE63B4446396169D4AA9C1,SHA256=AB278A73E11B00F53AEA894A3A33A39CFEA058CE30DB24EA56E685E004B88F14,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026222Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:31.942{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50941-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000045087Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:35.786{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D66BFF2F1EF859321934FA40B8E4249A,SHA256=17984D25055E86CBF8A0F341ACFBFBAC35A24E5EFBCC76679433C1AF3D8FD265,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026224Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:35.283{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8DA3C3F6983442B377679DA1082E67B4,SHA256=9182B7ADD106C6C419C6A3FBAA931A654E182A208FBD290712F2607B6D23EB1E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045089Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:36.804{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=88EB0B62BAAA9C797CB41997DEF22720,SHA256=9045F7962C4D52A2E38695023A42B6B5DE27DF14C055A87E9A45C62E9AD2CA74,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026225Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:36.283{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9BCA1116611C3C051819E4C8E0BE2D1C,SHA256=0A8CE5D33D826D7D855400BD3011F2545B226BF6FCA12BF0A4E8B2BD2EB7101D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045088Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:36.251{323FE7D8-022E-6136-1000-00000000F001}404NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=6F724AF5A415AF6145B341639E669202,SHA256=65626B977EFA946B5C4D861AA6E48CD61114F38A648EEDFF79EC9C3B807B4585,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045090Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:37.834{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC1D3AE3BEFB722163187ABE72E8BC02,SHA256=ED6D10D48E031DB9E00A2C945EE54448A2232F37A238FD9AB6E70D477DAC66D2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026226Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:37.314{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B5362A72DD21B22265B1EC5E4968BCC,SHA256=9C0EF6F460167086679C83C8B25C4F24D0883F1E123D64F4CB167D45703A2F55,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045091Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:38.865{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3CC26715B6A3E854391E42CCC362258F,SHA256=65619DE5AAAFB196F78790635A69858AE93553FDB26BB27ED72A25705640796C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026227Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:38.314{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D962FE5AF8E0D95B55C19799921B5B10,SHA256=957374AD2144C9EE93CF55EF0BC79475957E5FE8A5713F5D1DD119B7B6BFD201,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045094Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:39.886{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B17C9AB4D9CEE70CF06F8ADC03C70A86,SHA256=716072FA2BC26E140628C18D67CA8EA829B52EF2F181BB15E539F0DF2A61426B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026229Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:39.326{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4730356D27BF3BC51E2EE657010AF86,SHA256=5B6492979377C3D50E362B378CCB8E2CEC5C045A2BA0B555D0DF2E407D579498,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026228Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:36.958{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50942-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000045093Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:36.842{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51692-false10.0.1.12-8000- 23542300x800000000000000045092Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:39.449{323FE7D8-0617-6136-F403-00000000F001}4476ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c5ep525d.default-release\permissions.sqlite-journalMD5=FBB99CC5E0A5E7A4F8C43E0947483603,SHA256=44071743AF8E4005551CFE063B9C5A1B8F9AC81453DD0FA1FEE0708BE825ECFE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045095Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:40.901{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=63926572F765CEB149F5C4C52F7D41BA,SHA256=88236EAC568535CDBBCD8B1FBBBFF57A4DEDC278B180B011EBF59AA45918E4F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026230Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:40.326{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E4D8A8FB75123A211EFE5546F80FD279,SHA256=3D7A5F7A902A61072DA216101EFBA88A0EAACA3544101833F355287C5BE3CC06,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045096Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:41.916{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0F5AD8AE09E347ED2F2446DF2830C2AB,SHA256=49E7F46AFA8C9EB78F62DA2D807B05CD3AD62F629D811ACFCB6C54295E64CD75,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026231Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:41.341{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=185D8CA2B55AF89A130016EE7C857402,SHA256=B48D3138CED059B501F31AD53241B582E20377796B449F3FEB8598E308A9D6FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045097Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:42.931{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36A04A9F602252746CFA2036653E9CAF,SHA256=29CCF8775CA4B9C99BA866FA873C1E64E8FBB2D1F4BB90C0489064428D932219,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026232Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:42.357{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32D39C68723CC853F2E19F5DDB9652D1,SHA256=2FA125B4E44475FE808608C1020BA8D61EB671491E0A1ED625A9C9E0AA36EB2B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045098Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:43.961{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E55F88089D5D5A882876A09591B3FDF1,SHA256=EFA0CA515CED64923AA504A6CED726244080491C74882902E3D22D1A169E49C3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026233Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:43.420{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F99F2DA41EC724E857FFBC273E465AF4,SHA256=300179AB07BFFCBD8E37F0270CDA2B300E96DD5B7BD3F5FD02C8A406FC986962,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026234Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:44.435{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B00E4CDB6E02D71E8715ACA13AFF91B2,SHA256=353369CFD85E6F3724545ECFF5CBBD846C4C52621C081C72F882D51C7A4BE0AA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026236Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:43.001{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50943-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026235Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:45.451{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BE6121AFAA021A35AA86A962C31BE386,SHA256=4FFC164E2295631210778315655748D9281567B15602778A9818C4B40E2F6511,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045100Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:42.853{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51693-false10.0.1.12-8000- 23542300x800000000000000045099Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:44.998{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2861EC038DFC623300414270436349B4,SHA256=6C9472A30E89CC1DB78D7E1CE5B2BC10CB270086EBE79EA13FC1112F48D2465E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026237Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:46.466{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD857553B0DCD29F03AD373A08FF8247,SHA256=37A1CFF47CCC2004BAC576E1182F7CA3129F2630B616DB53B1F9168A4A297D18,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045101Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:46.028{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=601193759FFFA87608A386B713DB835C,SHA256=1BA8273C3895FD495FFBF7A91312F0647BD027EAE021F2F766594417C43582F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026238Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:47.466{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD09D9CB09A6EF3FB7399FC32D7FD7DF,SHA256=12705A4A8F422847615CAE2AE8C1E07B3E3C4C6EF82F2BC6C548CC4AFDFDEF3F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045102Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:47.061{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=822701FBF03A0E16D2457A5BBB677D22,SHA256=91054E49AA0C6A1730359548133F6643F6E931A11EAB238199088FBA28639E48,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026239Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:48.498{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64278EE69BB8AC52625B1584B68FBC68,SHA256=22985C3683E84AF6913E3A448C62674A18404990D14AF67A245D3B8747ADA3C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045103Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:48.062{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3E0FF722D14FA0ABCB8F41CD66B7D492,SHA256=525A10F807F676EFE12F0793F9B37C87DA054D434EA89372B30C1B2AF036A1E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026240Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:49.498{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B4AD0E552145CB504DA71F921F0D493C,SHA256=CAD4B73E2E519A3F6A50E8A4E38EEC672B3047FBEC6A4951FA23296A8A58CF69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045104Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:49.079{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC8CD217258487C268018376DC6A3448,SHA256=11D4408AD9938A2FED1B5816C1F2ADC63CC88A15168FC2008407CB3F552C76EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026241Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:50.513{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=66B7754CE3B296CB1C66A54A84B483C6,SHA256=EFAB74736E929DF373788DA9964611E971F662508AD92447A19F9D64E656BE33,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045105Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:50.098{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=55D6ACE4FA0811424DF3B71EDEA3C84A,SHA256=5A87E9F81E10F12651E736FD81B51CAA44A5A0B0C7D01C81E7F43A2CE5B450A2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026244Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:49.001{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50944-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026243Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:51.623{FFF7FB96-041E-6136-1200-00000000F101}1020NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=6E6525C7572086B0D06BD00F3D9E287E,SHA256=B91E7417206AEDB1B823CF83220EC4021A3F6C1ACAA2152495B09C0A4A32D6DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026242Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:51.529{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B16104EDA7DEBCA91F221191F992FE4,SHA256=89882DAADBFFBD3DE972441EBD94F54701811C84FFCC54A05B585C918E998CA4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045107Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:51.129{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC59EEAFD4D263FF07ACCD95B8CBE1E2,SHA256=E9B1D47DCD3CA5F9CCBBDB908AF169DC1AB4E851C174F6FD4E57E337D073BD99,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045106Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:48.672{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51694-false10.0.1.12-8000- 13241300x800000000000000026255Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000026254Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x005abc35) 13241300x800000000000000026253Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7a31c-0xfc7bef7e) 13241300x800000000000000026252Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7a325-0x5e40577e) 13241300x800000000000000026251Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7a32d-0xc004bf7e) 13241300x800000000000000026250Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000026249Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x005abc35) 13241300x800000000000000026248Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7a31c-0xfc7bef7e) 13241300x800000000000000026247Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7a325-0x5e40577e) 13241300x800000000000000026246Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-SetValue2021-09-06 13:44:52.826{FFF7FB96-041D-6136-0B00-00000000F101}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7a32d-0xc004bf7e) 23542300x800000000000000026245Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:52.529{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4ECE1DC232D0288807584CFAC8214094,SHA256=B55E96EA052688561515FA9884E55A25D16259112AA10D940A7DA36783259C36,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045108Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:52.144{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3FB421357749C97EA1D6D01F42AA218A,SHA256=3DD5804FC8C642E9A519BD31CFDA776AECF07F2776725F62B581880767C56CC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026256Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:53.544{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41CAB7C61EC7D410BE9D62C3A897CF14,SHA256=C1FF4A120E28170603F46C65B62E975EA259EC6D963CF6DBCA3768E6FD3B6E3A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045109Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:53.159{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E865D9E21CE5C7FBB07246ACF0870648,SHA256=BE641A3609CC579355E9DF666767B830BD6F347BBD848B0D88AA7E22233A184A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026257Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:54.544{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F8DF04616C73DEFC94AEA054F55AB7D6,SHA256=6BB55D1A9BB817288421F63A0ADAD09D30FDEA75A0C01BA0A7C5E647FA00B0BC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045110Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:54.179{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7EB1C74D27EB3B3B75DB4D18916AF46,SHA256=F0F6F5E94378E71371836BDD9CF077328D4CD85D6CCDBAD19CF7EF3726FEDCAC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026258Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:55.560{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97549DD08BC320A33D4FCDA20434B97A,SHA256=A90A56987726180F969903190D0FD2F07610081A7E6DE1FC1E015770419DF1D3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045112Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:53.702{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51695-false10.0.1.12-8000- 23542300x800000000000000045111Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:55.195{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A13FF856269F4EA5EF3D48C3699A8EAA,SHA256=20C3F2A72D0BCEDB5C8EF30DF01B08452F609ECAF06200AFA672335A09542478,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026259Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:56.560{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=495994296A00056F737D13D2A1B61652,SHA256=1D4926A797C8777F78779813403FA9458030B3109F749C4A9D5DC1FAC63ADBD2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045113Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:56.209{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F499687719333F459054B394D6D40B74,SHA256=0D659EEED19D2736F714A06805EF0F3C7315351AECC9A728110126A11B7A670A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026261Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:54.907{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50945-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026260Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:57.576{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F20D0995EA9F5A98C6073FCC02D7980A,SHA256=B778E7BD0BF1776EB3AB7B8BFC5C3743D5D37EFB1F4149CCC3B5A4393084D296,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045114Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:57.224{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D908B6175037AD974F32E926F174BED5,SHA256=31C707AC40C464AADB1E5177D59587654288753CE962E4B7C846155CEAB79A14,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026262Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:58.576{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB897D5A273558F0DAC4F2FC376DBAF5,SHA256=05274AFC7B4C8B2C91F6B2669085BF1C41BE26BA20B348568173EE8824A32335,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045115Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:58.255{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C724C9AEE149E902B844BFE72344181,SHA256=E81007265C1689E5BA1F26306517CFA389BDE7F4EFEAD77FA26E6EDB9DEAE711,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026263Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:44:59.596{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A32BC2758B93D74C8DD5E5685D533D59,SHA256=99C1F66550F4E4B2177001A60682ED4140B5F22E2C53F42E2371D0C9C4ACDBB0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045116Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:59.276{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F706B18A804CBA9E2DCC2D8F0F75D0A3,SHA256=F3554DD126D68051F591949F27BB6A7FC9E75D6631523318EB06B33B2D5EB8A3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026264Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:00.612{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5A9BE78EF5F70D3D1A8BDE2C234A0EF6,SHA256=DFDAFF2D05122C5DB1278054AE6FFB18CE8AD8FBD3C47EE619B134E1DE9BDF09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045118Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:00.291{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=82E9E2A82094F659C06EE2B016FAED52,SHA256=2BC8FD52468F880CF42F9ABB1032E50926FE44EDEF2CE7C67E7E1773E585D0F5,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000045117Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-SetValue2021-09-06 13:45:00.038{323FE7D8-022E-6136-1100-00000000F001}492C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7a325-0x62fa0514) 23542300x800000000000000026265Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:01.643{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F8F506EA66B855F0324772F5430968D,SHA256=2B8F80A8995156ABAEFD1852CE2059CEDE8BCD0ED4E2E7BE1DD4C4BCF6225B4A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045119Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:01.322{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D3ACCECBAB0882AE191066BB38337A1F,SHA256=C87B45E5A6DE9D4D0E2F42F03E7FA673D04875BAA923D38EEA29AB2E637F6BF3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026266Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:02.674{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C722889090D0777475705243668AEDAA,SHA256=A608584BADA39E197F659B89B24FAF44929C92D43AE0631FFA0A89B26A339FB1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045122Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:02.337{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD50CF70C5EB7990A795BDD746181DDB,SHA256=F5253CE76D349BB4CF2E7418CAE134F668AF130041DC294CEA61E7DB7F6F68BF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000045121Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:59.714{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51696-false10.0.1.12-8000- 354300x800000000000000045120Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:44:59.613{323FE7D8-022E-6136-1100-00000000F001}492C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.14win-dc-456.attackrange.local123ntpfalse169.254.169.123-123ntp 23542300x800000000000000026268Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:03.705{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=23F3FAC7869257363B3E3847991989A4,SHA256=23A33984CBF7695CB75CDC54FC5815EDBA24E6D9AAA73F10181EC11E3ED2FA77,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045123Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:03.352{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64712E31A67044DF6228618AAF108AB9,SHA256=32C9354E4470C66384FB04C3E23B68356319ACA70F70018029DD8E378AADF28D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026267Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:00.896{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50946-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000026269Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:04.705{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8CCA3008B160C2BC67E55223612FC4F,SHA256=B650A5426C66CDD6585FAB66E320DD15FA8A9BCB6921394FAC9858D5239FDE55,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045132Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.474{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B60-6136-F408-00000000F001}6932C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045131Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.471{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045130Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.471{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045129Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.471{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045128Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.471{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045127Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.471{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1B60-6136-F408-00000000F001}6932C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045126Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.470{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B60-6136-F408-00000000F001}6932C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045125Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.469{323FE7D8-1B60-6136-F408-00000000F001}6932C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000045124Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:04.352{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9933B6B94A48F13B261E8DC02699A948,SHA256=097934525F136542FBB83DECC5B77C90113F9741EA41DB07BE917BA49308BB64,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026297Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.799{FFF7FB96-049C-6136-9F00-00000000F101}416NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=8750129871E9EE1AE91141A9C8CE0636,SHA256=C066BDADBFB71ECE261FD3732B901F6742FA9775152EB875557B7910A2C937F4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026296Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B61-6136-6E06-00000000F101}3724C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026295Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026294Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026293Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026292Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026291Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026290Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026289Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026288Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026287Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026286Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1B61-6136-6E06-00000000F101}3724C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026285Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.736{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B61-6136-6E06-00000000F101}3724C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026284Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.737{FFF7FB96-1B61-6136-6E06-00000000F101}3724C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026283Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.721{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A88876826EC5FD8EA7F1A4E7D1AF8F5D,SHA256=B1D1294175DC5853F9F86382903D5FEC004BD516C960792EDC8DA923C9A47614,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045152Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B61-6136-F608-00000000F001}4404C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045151Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045150Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045149Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045148Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045147Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1B61-6136-F608-00000000F001}4404C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045146Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.804{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B61-6136-F608-00000000F001}4404C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045145Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.805{323FE7D8-1B61-6136-F608-00000000F001}4404C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000045144Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.473{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DE7CD61CC8F6EF0EC9C1C92038774B03,SHA256=AA8CD3518016F1B24735C7623AFFA7C6DFD4F4BAA7B71E6EB63B221BD914087E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045143Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.473{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9FE7A79E960142A7437BA7A7AF55392E,SHA256=957CFE084E5FFD89CAEF3A1D47A1F3373C15E4101B353FBD4D6D846976B358C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045142Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.373{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE95F07879F0EA036D27AE109321ACFD,SHA256=D77EA99EE7B3E406BD3A2AE1EBB94044FA72375754FB56C63665D6AE7053F26B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026282Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B61-6136-6D06-00000000F101}4060C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026281Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026280Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026279Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026278Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026277Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026276Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026275Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026274Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026273Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026272Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-041D-6136-0500-00000000F101}412528C:\Windows\system32\csrss.exe{FFF7FB96-1B61-6136-6D06-00000000F101}4060C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026271Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B61-6136-6D06-00000000F101}4060C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026270Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.065{FFF7FB96-1B61-6136-6D06-00000000F101}4060C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000045141Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.321{323FE7D8-1B61-6136-F508-00000000F001}66486312C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045140Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B61-6136-F508-00000000F001}6648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045139Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045138Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045137Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045136Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045135Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-022C-6136-0500-00000000F001}408524C:\Windows\system32\csrss.exe{323FE7D8-1B61-6136-F508-00000000F001}6648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045134Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.136{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B61-6136-F508-00000000F001}6648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045133Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.137{323FE7D8-1B61-6136-F508-00000000F001}6648C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000045154Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:06.651{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DE7CD61CC8F6EF0EC9C1C92038774B03,SHA256=AA8CD3518016F1B24735C7623AFFA7C6DFD4F4BAA7B71E6EB63B221BD914087E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045153Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:06.389{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B85280013642FDD94A68EC5EBF449BDC,SHA256=7D0FA8A7DC40243413D80A4BE1E27EB8A1E97DA7F42820F99423F3D8C5EE43AC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026313Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.408{FFF7FB96-1B62-6136-6F06-00000000F101}9322996C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026312Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B62-6136-6F06-00000000F101}932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026311Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026310Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026309Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026308Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026307Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026306Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026305Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026304Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026303Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026302Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B62-6136-6F06-00000000F101}932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026301Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.236{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B62-6136-6F06-00000000F101}932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026300Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.237{FFF7FB96-1B62-6136-6F06-00000000F101}932C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026299Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.096{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EFD10DBE37218069B00CD02D4CCA35F1,SHA256=918AEB829E06D82428BA6A2C5B1F6C1408D8A307BA5457B9EAB66ABFD514F9F6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026298Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:06.096{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A2904CF23C91487CEF2EFEC9F110178,SHA256=189A1C2EF17DDB9A756B9A3D7CACE1E46512FA0685609E435493D7C762D7C7E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045158Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:07.404{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A5513C2C79BEB4780CC05A20C6D84F9,SHA256=8CFFE7FB807366BD6EA743E5DDC70F83F764A659D58A7B56C197157641E5770E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026344Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.955{FFF7FB96-1B63-6136-7106-00000000F101}32042508C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026343Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B63-6136-7106-00000000F101}3204C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026342Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026341Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026340Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026339Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026338Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026337Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026336Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026335Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1B63-6136-7106-00000000F101}3204C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026334Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026333Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026332Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.752{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B63-6136-7106-00000000F101}3204C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026331Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.753{FFF7FB96-1B63-6136-7106-00000000F101}3204C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000026330Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.487{FFF7FB96-1B63-6136-7006-00000000F101}40003880C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000026329Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.299{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EFD10DBE37218069B00CD02D4CCA35F1,SHA256=918AEB829E06D82428BA6A2C5B1F6C1408D8A307BA5457B9EAB66ABFD514F9F6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026328Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B63-6136-7006-00000000F101}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026327Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026326Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026325Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026324Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026323Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026322Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026321Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026320Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026319Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041D-6136-0500-00000000F101}412428C:\Windows\system32\csrss.exe{FFF7FB96-1B63-6136-7006-00000000F101}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026318Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026317Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B63-6136-7006-00000000F101}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026316Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.254{FFF7FB96-1B63-6136-7006-00000000F101}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026315Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:07.252{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=75B752306D692FF36CA27B7477324E89,SHA256=FE9F23A4F328DCA46290E9A9363752CC66D2B19805D72B644D923BBFA6B4C133,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000026314Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.631{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50947-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000045157Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.661{323FE7D8-02C4-6136-D600-00000000F001}376C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-456.attackrange.local51698-false10.0.1.12-8000- 354300x800000000000000045156Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.212{323FE7D8-022C-6136-0B00-00000000F001}624C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51697-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 354300x800000000000000045155Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:05.211{323FE7D8-023F-6136-2800-00000000F001}2952C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-456.attackrange.local51697-true0:0:0:0:0:0:0:1win-dc-456.attackrange.local389ldap 10341000x800000000000000045177Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.872{323FE7D8-1B64-6136-F808-00000000F001}28923488C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045176Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B64-6136-F808-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045175Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045174Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045173Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1B64-6136-F808-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045172Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045171Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045170Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B64-6136-F808-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045169Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.688{323FE7D8-1B64-6136-F808-00000000F001}2892C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000045168Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.419{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E4A8AC77CD07C5FB98EB39E5DBFDCE66,SHA256=36F7AE796BE4EEF094FA25C8FAF1B10F634A1CBEF458D554DAF48B46ECFEEC09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026361Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.768{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=09F6DA98B8494824B080116F57C279FE,SHA256=8DAC83315A5F687DA39E93863F6C41275A9936F1342F81241C0A649C64DF0534,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026360Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.581{FFF7FB96-1B64-6136-7206-00000000F101}7361472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000026359Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.455{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B4AEC5927D7B230D9C7B481855449E7,SHA256=E281473926EAD3A0A1E73B6A41B80CCEA1D7C943F8A46A2E71D0B2ED45F3FAF5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026358Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B64-6136-7206-00000000F101}736C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026357Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026356Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026355Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026354Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026353Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026352Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026351Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026350Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026349Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026348Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B64-6136-7206-00000000F101}736C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026347Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.424{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B64-6136-7206-00000000F101}736C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026346Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:08.425{FFF7FB96-1B64-6136-7206-00000000F101}736C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000026345Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:05.927{FFF7FB96-04A4-6136-CD00-00000000F101}4076C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-353.attackrange.local50948-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000045167Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.204{323FE7D8-1B64-6136-F708-00000000F001}69763856C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045166Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B64-6136-F708-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045165Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045164Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045163Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045162Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045161Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-022C-6136-0500-00000000F001}4083512C:\Windows\system32\csrss.exe{323FE7D8-1B64-6136-F708-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045160Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.019{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B64-6136-F708-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045159Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:08.020{323FE7D8-1B64-6136-F708-00000000F001}6976C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000045196Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B65-6136-FA08-00000000F001}5132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045195Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045194Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045193Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045192Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045191Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1B65-6136-FA08-00000000F001}5132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045190Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.835{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B65-6136-FA08-00000000F001}5132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045189Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.836{323FE7D8-1B65-6136-FA08-00000000F001}5132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000045188Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.572{323FE7D8-1B65-6136-F908-00000000F001}44882376C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000045187Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.471{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3D06A9BF803F2BED06B2B25D7F8CA986,SHA256=4799283E2E81630D762E4CEB93DFAF263610A52CD5FBFF05FCE0255B10E4F80A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000026375Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-049C-6136-A300-00000000F101}29283756C:\Windows\system32\conhost.exe{FFF7FB96-1B65-6136-7306-00000000F101}2960C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026374Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026373Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026372Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026371Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026370Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026369Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026368Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026367Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026366Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041E-6136-0C00-00000000F101}7283896C:\Windows\system32\svchost.exe{FFF7FB96-041F-6136-1D00-00000000F101}1952C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000026365Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-041D-6136-0500-00000000F101}412960C:\Windows\system32\csrss.exe{FFF7FB96-1B65-6136-7306-00000000F101}2960C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000026364Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.096{FFF7FB96-049C-6136-9F00-00000000F101}4162952C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{FFF7FB96-1B65-6136-7306-00000000F101}2960C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000026363Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.097{FFF7FB96-1B65-6136-7306-00000000F101}2960C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{FFF7FB96-041D-6136-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{FFF7FB96-049C-6136-9F00-00000000F101}416C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000026362Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:09.080{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CF2DF504DF3BB091356104AF1B6553FE,SHA256=D8BE6FF8E02571F61C8C3677E9E53C737CCCE3AD59BB5FC87803BCB385CE1C0A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000045186Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-02BC-6136-AB00-00000000F001}38723380C:\Windows\system32\conhost.exe{323FE7D8-1B65-6136-F908-00000000F001}4488C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045185Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045184Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045183Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045182Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-022E-6136-0C00-00000000F001}8486244C:\Windows\system32\svchost.exe{323FE7D8-023F-6136-2F00-00000000F001}2368C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000045181Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-022C-6136-0500-00000000F001}408424C:\Windows\system32\csrss.exe{323FE7D8-1B65-6136-F908-00000000F001}4488C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000045180Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.349{323FE7D8-02BC-6136-A700-00000000F001}10363440C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{323FE7D8-1B65-6136-F908-00000000F001}4488C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000045179Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.350{323FE7D8-1B65-6136-F908-00000000F001}4488C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{323FE7D8-022C-6136-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{323FE7D8-02BC-6136-A700-00000000F001}1036C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000045178Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:09.050{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=115F4196EBFF391F81F5134AD1D31831,SHA256=A3B3A5FBB79C078AEE2E7AD87933E5FA353CA124BB12E35BDCA75EACAE43E418,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045198Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:10.488{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3FDC7E48C5D48A2FFDC237056F82851D,SHA256=C304F28C88E411BE50D478FA20E63DD241D645F70081BB0E2E25EBF5E7DF7F65,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026377Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:10.143{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4EBB4B335554A50C2F82B493A3F950D5,SHA256=68F6C53DCDEAD0954D82DE95C5E2102AF663FB074827909EF4457F8A40AC5338,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026376Microsoft-Windows-Sysmon/Operationalwin-host-353.attackrange.local-2021-09-06 13:45:10.111{FFF7FB96-04A9-6136-D600-00000000F101}1184NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4BCFC63D60D11DFECE2E1919F46223BB,SHA256=2B131073E2C59849C8BBF2B3212B2459C8D027364A24172C7F82BE32D7735AC9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045197Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:10.350{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F4E8BCEFB907C2505CAED669B89941EF,SHA256=69693231715CB58F3F11CF770782E30BC2C69BCBB15453EF97EB0DD7983A907E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000045199Microsoft-Windows-Sysmon/Operationalwin-dc-456.attackrange.local-2021-09-06 13:45:11.550{323FE7D8-02C9-6136-DF00-00000000F001}3940NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C42230C9B73FFC8AEE90871D45FBCE37,SHA256=2A442F22FEE08CF70FF3A89C24D58C630ACD0AA366493589CFB094E99604747E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000026378