10341000x800000000000000023104422Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.728{AD5E2759-AA37-6196-70C7-09000000F101}31326008C:\Windows\system32\Dism.exe{AD5E2759-AA37-6196-71C7-09000000F101}4380C:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\dismhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\Dism\DismCore.dll+273f6|C:\Windows\System32\Dism\DismCore.dll+8eaa|C:\Windows\System32\Dism\DismCore.dll+58d4|C:\Windows\system32\Dism.exe+cd60|C:\Windows\system32\Dism.exe+4bd3|C:\Windows\system32\Dism.exe+3c84|C:\Windows\system32\Dism.exe+26b9|C:\Windows\system32\Dism.exe+1db1|C:\Windows\system32\Dism.exe+21fed|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000023104421Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.738{AD5E2759-AA37-6196-71C7-09000000F101}4380C:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismHost.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Host Servicing ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationDismHost.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\dismhost.exe {21E0372D-E125-424B-88FA-249CD7AD93B8}C:\Users\Administrator\Desktop\WIN-HOST-874\Administrator{AD5E2759-A1B1-6168-DD52-B32300000000}0x23b352dd2HighMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\System32\Dism.exeDism /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quiet 11241100x800000000000000023104420Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.728{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-winsvc-l1-1-0.dll2021-11-18 19:32:07.728 11241100x800000000000000023104419Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.728{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-private-l1-1-1.dll2021-11-18 19:32:07.728 11241100x800000000000000023104417Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.728{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-private-l1-1-0.dll2021-11-18 19:32:07.728 11241100x800000000000000023104416Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.728{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-management-l2-1-0.dll2021-11-18 19:32:07.728 11241100x800000000000000023104415Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.728{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-management-l1-1-0.dll2021-11-18 19:32:07.728 11241100x800000000000000023104414Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-core-l1-1-1.dll2021-11-18 19:32:07.712 11241100x800000000000000023104413Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-core-l1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104412Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-security-sddl-l1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104411Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-security-provider-L1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104410Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-security-lsapolicy-l1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104409Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Security-Lsalookup-L2-1-1.dll2021-11-18 19:32:07.712 11241100x800000000000000023104408Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Security-Lsalookup-L2-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104407Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-security-cryptoapi-l1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104406Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-security-base-l1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104405Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-EventLog-Legacy-L1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104404Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-Provider-L1-1-0.dll2021-11-18 19:32:07.712 11241100x800000000000000023104403Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.712{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-Legacy-L1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104402Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-Controller-L1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104401Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-eventing-consumer-l1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104400Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104399Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-devices-config-L1-1-1.dll2021-11-18 19:32:07.697 11241100x800000000000000023104398Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-devices-config-L1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104397Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-xstate-l2-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104396Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-xstate-l1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104395Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-wow64-l1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104394Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-version-l1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104393Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-util-l1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104392Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-url-l1-1-0.dll2021-11-18 19:32:07.697 11241100x800000000000000023104391Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.697{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-timezone-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104390Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-threadpool-private-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104389Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-threadpool-legacy-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104388Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-threadpool-l1-2-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104387Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-sysinfo-l1-2-1.dll2021-11-18 19:32:07.681 11241100x800000000000000023104386Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-sysinfo-l1-2-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104385Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-sysinfo-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104384Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-synch-l1-2-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104383Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-synch-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104382Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-stringloader-l1-1-1.dll2021-11-18 19:32:07.681 11241100x800000000000000023104381Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-stringansi-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104380Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-string-obsolete-l1-1-0.dll2021-11-18 19:32:07.681 11241100x800000000000000023104379Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.681{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-string-l2-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104378Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-string-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104377Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-shutdown-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104376Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104375Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-shlwapi-legacy-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104374Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-rtlsupport-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104373Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-registry-l2-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104372Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-registry-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104371Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.666{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-realtime-l1-1-0.dll2021-11-18 19:32:07.666 11241100x800000000000000023104370Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-profile-l1-1-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104369Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processtopology-obsolete-l1-1-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104368Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processthreads-l1-1-2.dll2021-11-18 19:32:07.650 11241100x800000000000000023104367Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processthreads-l1-1-1.dll2021-11-18 19:32:07.650 11241100x800000000000000023104366Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processthreads-l1-1-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104365Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processenvironment-l1-2-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104364Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processenvironment-l1-1-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104363Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-privateprofile-l1-1-1.dll2021-11-18 19:32:07.650 11241100x800000000000000023104362Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-privateprofile-l1-1-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104361Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-namedpipe-l1-1-0.dll2021-11-18 19:32:07.650 11241100x800000000000000023104360Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.650{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-memory-l1-1-2.dll2021-11-18 19:32:07.650 11241100x800000000000000023104359Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-memory-l1-1-1.dll2021-11-18 19:32:07.634 11241100x800000000000000023104358Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-memory-l1-1-0.dll2021-11-18 19:32:07.634 11241100x800000000000000023104357Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-localization-obsolete-l1-2-0.dll2021-11-18 19:32:07.634 11241100x800000000000000023104356Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-localization-l1-2-1.dll2021-11-18 19:32:07.634 11241100x800000000000000023104355Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-localization-l1-2-0.dll2021-11-18 19:32:07.634 11241100x800000000000000023104354Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-libraryloader-l1-1-1.dll2021-11-18 19:32:07.634 11241100x800000000000000023104353Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-libraryloader-l1-1-0.dll2021-11-18 19:32:07.634 11241100x800000000000000023104352Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll2021-11-18 19:32:07.634 11241100x800000000000000023104351Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.634{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll2021-11-18 19:32:07.634 11241100x800000000000000023104350Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-kernel32-legacy-l1-1-1.dll2021-11-18 19:32:07.619 11241100x800000000000000023104349Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-kernel32-legacy-l1-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104348Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-io-l1-1-1.dll2021-11-18 19:32:07.619 11241100x800000000000000023104347Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-io-l1-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104346Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-interlocked-l1-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104345Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104344Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-heap-l1-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104343Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-handle-l1-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104342Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-file-l2-1-1.dll2021-11-18 19:32:07.619 11241100x800000000000000023104341Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.619{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-file-l2-1-0.dll2021-11-18 19:32:07.619 11241100x800000000000000023104340Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-file-l1-2-1.dll2021-11-18 19:32:07.603 11241100x800000000000000023104339Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-file-l1-2-0.dll2021-11-18 19:32:07.603 11241100x800000000000000023104338Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-file-l1-1-0.dll2021-11-18 19:32:07.603 11241100x800000000000000023104337Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-fibers-l1-1-1.dll2021-11-18 19:32:07.603 11241100x800000000000000023104336Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-fibers-l1-1-0.dll2021-11-18 19:32:07.603 11241100x800000000000000023104335Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-errorhandling-l1-1-1.dll2021-11-18 19:32:07.603 11241100x800000000000000023104334Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-errorhandling-l1-1-0.dll2021-11-18 19:32:07.603 11241100x800000000000000023104333Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.603{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-delayload-l1-1-0.dll2021-11-18 19:32:07.603 11241100x800000000000000023104332Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-debug-l1-1-1.dll2021-11-18 19:32:07.587 11241100x800000000000000023104331Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-debug-l1-1-0.dll2021-11-18 19:32:07.587 11241100x800000000000000023104330Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-datetime-l1-1-1.dll2021-11-18 19:32:07.587 11241100x800000000000000023104329Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-datetime-l1-1-0.dll2021-11-18 19:32:07.587 11241100x800000000000000023104328Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-console-l1-1-0.dll2021-11-18 19:32:07.587 11241100x800000000000000023104327Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-comm-l1-1-0.dll2021-11-18 19:32:07.587 11241100x800000000000000023104326Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-com-l1-1-0.dll2021-11-18 19:32:07.587 11241100x800000000000000023104325Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.587{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-base-util-l1-1-0.dll2021-11-18 19:32:07.587 11241100x800000000000000023104324Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.572{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\WimProvider.dll2021-11-18 19:32:07.572 11241100x800000000000000023104323Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.572{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\VhdProvider.dll2021-11-18 19:32:07.572 11241100x800000000000000023104322Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.572{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\UnattendProvider.dll2021-11-18 19:32:07.572 11241100x800000000000000023104321Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.572{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\TransmogProvider.dll2021-11-18 19:32:07.572 11241100x800000000000000023104320Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.556{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\SmiProvider.dll2021-11-18 19:32:07.556 11241100x800000000000000023104319Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.556{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\ProvProvider.dll2021-11-18 19:32:07.556 11241100x800000000000000023104318Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.556{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\OSProvider.dll2021-11-18 19:32:07.556 11241100x800000000000000023104317Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.556{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\OfflineSetupProvider.dll2021-11-18 19:32:07.556 11241100x800000000000000023104316Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\MsiProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104315Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\LogProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104314Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\IntlProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104313Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\ImagingProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104312Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\IBSProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104311Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\GenericProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104310Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\FolderProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104309Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.541{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\FfuProvider.dll2021-11-18 19:32:07.541 11241100x800000000000000023104308Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.509{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DmiProvider.dll2021-11-18 19:32:07.509 11241100x800000000000000023104307Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.509{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismProv.dll2021-11-18 19:32:07.494 11241100x800000000000000023104306Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localEXE2021-11-18 19:32:07.494{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismHost.exe2021-11-18 19:32:07.494 11241100x800000000000000023104305Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.494{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismCorePS.dll2021-11-18 19:32:07.494 11241100x800000000000000023104304Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.494{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismCore.dll2021-11-18 19:32:07.494 11241100x800000000000000023104303Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.494{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\CompatProvider.dll2021-11-18 19:32:07.494 11241100x800000000000000023104302Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.494{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\CbsProvider.dll2021-11-18 19:32:07.494 11241100x800000000000000023104301Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.494{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\AssocProvider.dll2021-11-18 19:32:07.494 11241100x800000000000000023104300Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:32:07.478{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\AppxProvider.dll2021-11-18 19:32:07.478 10341000x800000000000000023104299Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.463{AD5E2759-5433-6143-0C00-00000000F101}7325984C:\Windows\system32\svchost.exe{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5126|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000023104298Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.463{AD5E2759-A1BE-6168-4461-04000000F101}57005728C:\Windows\system32\conhost.exe{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000023104294Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.447{AD5E2759-A1AF-6168-1D61-04000000F101}2172928C:\Windows\system32\csrss.exe{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000023104292Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.447{AD5E2759-AA37-6196-6FC7-09000000F101}25602332C:\Windows\system32\cmd.exe{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000023104291Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:07.447{AD5E2759-AA37-6196-70C7-09000000F101}3132C:\Windows\System32\Dism.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Image Servicing UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationDISM.EXEDism /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quietC:\Users\Administrator\Desktop\WIN-HOST-874\Administrator{AD5E2759-A1B1-6168-DD52-B32300000000}0x23b352dd2HighMD5=DD0DC0C490755CEA51413D940B31CF0C,SHA256=71C182B3550A7DCC61B56C2D7E363673574CD03000A5081C0A228D775ECAC133,IMPHASH=07D06C9BFC08891808D6DE5FCD00BC8A{AD5E2759-AA37-6196-6FC7-09000000F101}2560C:\Windows\System32\cmd.exe"C:\Windows\system32\cmd.exe" /c Dism /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quiet 23542300x800000000000000023104917Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.587{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\WimProvider.dllMD5=1B0C7DFB2240BA004B37904073624DB3,SHA256=F2C7DB522DDE968EDF49B03BC10978AAC4C42C745CA4A474627E8CEBBCEBB00A,IMPHASH=20D31D66F56B810094B1AA564C92009Dtruefalse - insufficient disk space 23542300x800000000000000023104916Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.572{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\VhdProvider.dllMD5=F37C8F5BF852151D9BF085687A8DEC6D,SHA256=6CDFC95C2F2ED3695D5EE8CF4367A6C7FB5707DA3C234CEE8FA8C1BBDE426DE7,IMPHASH=3CA997A1A0BD38B850B18DAED5E948DEtruefalse - insufficient disk space 23542300x800000000000000023104915Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.572{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\UnattendProvider.dllMD5=3DB4777B76FC1973A61754FAEC348981,SHA256=29A4C7379E5A0A7532C90B5ACE0DD99AB5311D03CC0BA6A4BCFB410D7D8B01AE,IMPHASH=4FA75E8720452554D61C8AC5FD64C43Ftruefalse - insufficient disk space 23542300x800000000000000023104914Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.572{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\TransmogProvider.dllMD5=5E82E2B7CFF045C7CDA8E33EAB186402,SHA256=0038B82E999C3DEF3980D39A8CAED9EA6B52A4FC9EF58BF3B3F5FC91F7748112,IMPHASH=7746C0E3C7D3763C5F13C90D4934087Btruefalse - insufficient disk space 23542300x800000000000000023104913Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.572{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\SmiProvider.dllMD5=C5C7A9E3121B91E51ECFBA6FB2985044,SHA256=FB519B9EEF4C3344D58C768BD3AD7ADCB0677EA7B998056B6A13620CB9E61412,IMPHASH=03C38376DA7CCE75E82EECACADA0EA03truefalse - insufficient disk space 23542300x800000000000000023104912Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.556{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\ProvProvider.dllMD5=5077063311C5708318C5FA3E255011ED,SHA256=97FA95102B6ACF00C70F140EE9FA4A73A6BE7C03E0F0D99AE58DB5E492CD0ECA,IMPHASH=D8DD764BFC0F1D9E403714D169018B83truefalse - insufficient disk space 23542300x800000000000000023104911Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.556{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\OSProvider.dllMD5=4868187A2F176074DB7F35E356F74D4F,SHA256=84C8C4C67C808871A278254304D985533F67D44391840F43674FC829014E1B60,IMPHASH=82A4D833A82D441391A9AA3027199337truefalse - insufficient disk space 23542300x800000000000000023104910Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.556{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\OfflineSetupProvider.dllMD5=86B7E8438B1125C479FD275B1BDDB9A7,SHA256=47FAF8671B25A30D7BCC47AD35926D70DB633A181FA6C276479B4408A526E63E,IMPHASH=B8B4A188EFC4F12D33591C6D319B6F12truefalse - insufficient disk space 23542300x800000000000000023104909Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.556{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\MsiProvider.dllMD5=EA19239A85416A488360FA564D312402,SHA256=F21591336CD1A24EE941827620405FA34414C1C349216B4B8083ECD1FFF17C29,IMPHASH=33E1132923056DDEFB0521726DA5B987truefalse - insufficient disk space 23542300x800000000000000023104908Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\LogProvider.dllMD5=F7DB4F104DBB56DF5A156E7329E80112,SHA256=7C67EFAF44D1413576B4575B1A4C975BCB10B64BEF13E6756E895D4DB9E61AA2,IMPHASH=FB695172E8A76C56E97CE435F8ED0220truefalse - insufficient disk space 23542300x800000000000000023104907Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\IntlProvider.dllMD5=0082903881275179642AE83EFA720310,SHA256=7CCF1625E6FBE4DB16F12AC037E4236A3EF269DEE47A157C68374C867941F9E8,IMPHASH=CFB81BC5FF922F23D605A653700FE666truefalse - insufficient disk space 23542300x800000000000000023104906Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\ImagingProvider.dllMD5=EEB4AA36BAD26A2C6216A1FF3439B58C,SHA256=44A6679425039DC870C297294C4B3323F6FA9DE5C7D16D7D0AB7E1254AFC75D3,IMPHASH=0264D9B4BFE54732ADF0E29BC73BF280truefalse - insufficient disk space 23542300x800000000000000023104905Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\IBSProvider.dllMD5=11DE34FCDB75E79A920D3B491F3E7BF0,SHA256=6B7C7AD8B1AD522B27B2CC5E4F76F56ADE4495D7D46CE4F997A68954F072AF17,IMPHASH=C755896FA14213058E34639A28868FBCtruefalse - insufficient disk space 23542300x800000000000000023104904Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\GenericProvider.dllMD5=397ED660129D40927A27B75A4B8FAE2E,SHA256=EAFCECFE911DABB4531E1331DDF2E119DCBB6B7A887D70BDE737EA76BE10EB74,IMPHASH=F55EE75573C110804DE5E50ACEEC1B06truefalse - insufficient disk space 23542300x800000000000000023104903Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\FolderProvider.dllMD5=6428B4D0C26DB23E9478F039891CD5C9,SHA256=55126BB099785C2F9CD32A30991082C47D62C8231D570A9D8A6F3CC599B25EE1,IMPHASH=B2CC5EDD42A866F7CB6CAE42DB969187truefalse - insufficient disk space 23542300x800000000000000023104902Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\FfuProvider.dllMD5=E27BC7F808E72F08372BA3C40B4B6344,SHA256=927B194432046C0D2ADF7C7B71E4BE85602C4D00A5D6EDA9F9DB9924E1C3447A,IMPHASH=8580AF5C1871319D05329DB2E96A8146truefalse - insufficient disk space 23542300x800000000000000023104901Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.540{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\WimProvider.dll.muiMD5=CC3B15540DDB521A300BAFF0BF4F902E,SHA256=33C06CC037DF1EBB72A15BCC2E09BC89DFEF7DD94441C650FD3D0C833122002A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104900Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\VhdProvider.dll.muiMD5=10536C56F02E68EBD13D0B2CE8665C6A,SHA256=06C3B71D251A8DD47D02EDBFBE84E0B6B1D67956DE4D3996031434CBAD728929,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104899Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\UnattendProvider.dll.muiMD5=B7E3676672BE6851EA13ADD879C2945E,SHA256=2D2D82EE842CD346B58DCAFAE6FEC46D491E0D15CFBE0D8964A4AB7F18C5AAB9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104898Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\TransmogProvider.dll.muiMD5=D5D596B1102DA565C2ED1FAAC170E758,SHA256=B5DBB36E947FD64AAF22C53F0A9634C7D72D4CC270C055B67E020920BF806909,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104897Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\SmiProvider.dll.muiMD5=CAD746ED5AF63E7FC49ED4A5A3984629,SHA256=016C6071B04E6D7E12AD9B8A85C002320331E01ED62922C573A1AC43BA0DD919,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104896Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\ProvProvider.dll.muiMD5=70AFEC86B6CF677BF8D3C713CA3281FB,SHA256=C8579EC95A51EB663FFC6145F0998C2F1930A6B8146C84C0A9094BCA4E5195A7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104895Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\OSProvider.dll.muiMD5=A464DFEDEA8520616AA9B2ACD166A77F,SHA256=54E985CFF256CEBE82E9EF3E814A5FDA9FF730BCB50265E9BA78DE65A4DE3F42,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104894Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\OfflineSetupProvider.dll.muiMD5=CED788DBD9D13D0490B2F642B0B051F6,SHA256=D5DBC0A52B598800EE14569859383525950B865F4816E47E2E73F79AA1C32A09,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104893Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\MsiProvider.dll.muiMD5=5AE9ABD6BB469F3AD7B3A4CCD40974BF,SHA256=C2CE66F2F218890AA76F8BAB68B4C0FDCED0688E694F912F3A5BFABFA6CDB5E7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104892Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\LogProvider.dll.muiMD5=0D4519BC8EB58A006E4A5EB993C0DCCF,SHA256=DAFFE67521F9B4657FBFEF9585234CB39293F9B866C0D97D66F675037515BB51,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104891Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\IntlProvider.dll.muiMD5=16ACB74928BC55FD4AAC316F3B92E1D7,SHA256=17CB486CADB679C75A27BA6C76E2FE714F4B8DA845E6F795759517D6734F0BC9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104890Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\ImagingProvider.dll.muiMD5=26F5BBF8D6EE90B4F47C18E93D1087FB,SHA256=F41738FEF7140176447ECF371B1117A485E48BA6F3E9AFAA8C4F883ABFAE62DA,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104889Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\IBSProvider.dll.muiMD5=0B09FE334215A8E736B2CF08A50D5204,SHA256=DCE9AD3B79F91BEBEDDFCD9E03F1557CB7C6114AC906081E9E046F807093CDF1,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104888Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\GenericProvider.dll.muiMD5=956B8B45B92321C0D5975EE9A6C5B773,SHA256=578541D71466CF61EF399023B34EDFCBD915142BE856534AD4D17D25E7CC9F3D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104887Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\FolderProvider.dll.muiMD5=DC4E4C2800DC6D98F7893044A21D246B,SHA256=8B4CE62F4E4294E701193C7AE393EB5EB29AA45932D376CB1A03728A140096AE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104886Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\FfuProvider.dll.muiMD5=5ECAD70AC2B3A95CBB42D6FE67D2F726,SHA256=C210389DBB9B7B4A802E4B0C3C708B6F55B086564A01E19CFB183B6AF916C30A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104885Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\DmiProvider.dll.muiMD5=38C2A1560C340537C3AE0CE04BDF7EAA,SHA256=52B06DFD85FB5AB1DCE2BE665CA144B1AE6658F518D1623D9B44C347C482B064,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104884Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\DismProv.dll.muiMD5=BD7B77B3EE9A12FF3F5446ECDF80B5C6,SHA256=B972A0B2C4682E9074441B481BD886DE19B8DB3DBA401B88E980B154C14D5A7E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104883Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\DismCore.dll.muiMD5=C901FF639EDFBBE710D6E5882F07CD24,SHA256=9BDA61D23DC50F9AFA82DA94B06B7B9C8229D5ED666D2F5270DAE13100815C27,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104882Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\CompatProvider.dll.muiMD5=A2A344CB32B6835744A36D877C952665,SHA256=A74D765B796638A921C4810D1712A08F7A37C9BA9E91F4DFDCB9727611C3D18D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104881Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\CbsProvider.dll.muiMD5=179B34BE97A383AF3E757031E7DA964B,SHA256=ABD3824664D1336EE849D89BA178606CC1B1E23E173752D8093F34A5580FA8F4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104880Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\AssocProvider.dll.muiMD5=386FE7AC95738A0CB6D25DEA662991F1,SHA256=22DC7317108A528BA92C853330598F628B93FFF27CAC34C2F501B806A75261D9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104879Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\en-US\AppxProvider.dll.muiMD5=9FF5081115C2C21D9F85AF7EE6D2CC63,SHA256=107B10A8C1426F1C0D703F06832D740A4CFDCAA596FA0EA147A32A736A7A2A4D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104878Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.525{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DmiProvider.dllMD5=FC76385FF00D4A93618D842B41716D8D,SHA256=BBD49A49CFFA8411FFA91B02541F5F3B5333FD9055BC129DDD3B36EB005C34D9,IMPHASH=062B279D8ED4374A0CD0C84620F4BE4Etruefalse - insufficient disk space 23542300x800000000000000023104877Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.509{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismProv.dllMD5=8C7D97E22045AE402EA896F514CEED81,SHA256=76D3202E11BA22D277532A14CAE60E596975C0D8C34C7BE154F453EB1F7C37EF,IMPHASH=0247CB1C8FD55E43A448E359883057DBtruefalse - insufficient disk space 23542300x800000000000000023104876Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.509{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismHost.exeMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424truefalse - insufficient disk space 23542300x800000000000000023104875Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.509{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismCorePS.dllMD5=FB88731B484D1FF4AFF5DB75A20799FA,SHA256=EA155388211E0C3CEF2C99BD5F341C9F93F1ECDA6F21096DB6F9DB2110686A52,IMPHASH=65E10DCEA11F7117C161DC7557B87689truefalse - insufficient disk space 23542300x800000000000000023104874Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.509{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\DismCore.dllMD5=F1AB58CACD95921A04225222D03CDEA0,SHA256=EDE89F377FD46F95639413411CDA072D9FF63E72A399B26AB4870094F145091B,IMPHASH=B7B56C790C8AB7134B0680D8DFE46658truefalse - insufficient disk space 23542300x800000000000000023104873Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.509{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\CompatProvider.dllMD5=E5C1D020198EBEC1D5ABA640C9A600D0,SHA256=A80FD2846E05AB491BDAAFCE8854A04549A852066B82B90D757D9B6A44ADA8C8,IMPHASH=2CDD615C09EED7B572606B2A0C0EFD2Ftruefalse - insufficient disk space 23542300x800000000000000023104872Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.509{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\CbsProvider.dllMD5=D4A64C7C50D0C6BE9F8770177E2264BF,SHA256=E6505F9DBE17DF9E7E52B5FE1720E1F6482B25D262A47A320CF438C5FD5A5797,IMPHASH=99D5DC4FF67AB12670853DD4E32E8358truefalse - insufficient disk space 23542300x800000000000000023104871Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.494{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\AssocProvider.dllMD5=56CB83B3454882509791FBA62832BC87,SHA256=5B01524CC03B6EB58CC9E0FF479014EAF89EE7FDE2791BFF871BC90274D200AC,IMPHASH=83F73507B4613B09C6FA825535D8A81Etruefalse - insufficient disk space 23542300x800000000000000023104870Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.494{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\AppxProvider.dllMD5=8F6792DF9EC54934B76A68B1D7B66ECA,SHA256=E57CB2D5CEC5E1354F4E31CD08ADA02FCAA0E2DEA4B28C8F61683BFA3E875C05,IMPHASH=F1558CACACA712554EBD5926B4B3FE52truefalse - insufficient disk space 23542300x800000000000000023104869Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.494{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-winsvc-l1-1-0.dllMD5=09934F0F7227B9489D117C26EC20CD14,SHA256=CBE408A0AFF90986A6A7DDF022F96302B4FADD08A0C3C166CAC7A64D6ABF041D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104868Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.494{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-private-l1-1-1.dllMD5=484ED248F1A72C6E4E6F6C3F5A3339ED,SHA256=00E14515FE6FEBBF3C2CFC89A6F1A3D6F48B3E7A5EB08D50DADF69CE3F34CC47,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104867Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.494{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-private-l1-1-0.dllMD5=FEBE55EA884F3C1EE45ADE2734AA6BE6,SHA256=CD51DF334A600117133C9C8100DDE766D980456988FD333A40BE5A81C8092340,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104866Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-management-l2-1-0.dllMD5=0D45D811001E0A7683A2B7CA8A883874,SHA256=F44E2A85D7507159AE115C85C3497C57BE4ECB2D6ADDB30A534110266D56F92F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104865Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-management-l1-1-0.dllMD5=C36912B3A28B06F5BB24FE9BE49DA4D3,SHA256=D737A832C0D595E8E52846C2D748B911D7155E372F43FBB10513CFDE0BBF83B7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104864Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-core-l1-1-1.dllMD5=A86D518BCF3970C17A1768792FDF37FF,SHA256=AB5CC1B14D6BB708B5C87C2622DA886E2119A6997E08108CCE36080385DAEE71,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104863Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-service-core-l1-1-0.dllMD5=A329C75641638E2FFA11087F614FD4C1,SHA256=5071AA303D436407D195EF37889F018BE7E350DA5E690793587458D4C6D308DB,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104862Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-security-sddl-l1-1-0.dllMD5=C6C6C3E4D7CFA93246362901750A94D9,SHA256=6E274ABE823EF8B30629A99D9F942794C9FE6D003021A0C5085B49A7D8611DDE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104861Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-security-provider-L1-1-0.dllMD5=207B5716605CA4850629F3E2FFFA07BB,SHA256=BE6E6284F69C76BE6366EA8D44D85BDBAB6A71DD42E8B5575CFDF671AD58DCA2,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104860Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-security-lsapolicy-l1-1-0.dllMD5=FE7AD7265E296947172B8C491E8109D2,SHA256=4D231AC65F0F54BFF45CACFFE7DF3109CF87F78D14960EC8F03654E605AC8ABF,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104859Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Security-Lsalookup-L2-1-1.dllMD5=EBD6475839F5C99FB8855A80E0FC2AF1,SHA256=F519C7AA6930DAC83A3045CEEE42F64F26FFC54254D5ABD1B0F7D99C47569A30,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104858Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Security-Lsalookup-L2-1-0.dllMD5=AC284A6251F5D26633AF48D918D09628,SHA256=F7A34B793AACF75DA4EAE843B6088C0BAAA8B835EA5F6A65E72EBD9A1479C8A8,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104857Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-security-cryptoapi-l1-1-0.dllMD5=DE0A49D4B2E9A5FA6762BD191C622B32,SHA256=AB12FEAF15CB313812B01AFE1198B62E72F7702D140830ABAD2CFB6251E82A7C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104856Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-security-base-l1-1-0.dllMD5=DC4B661366FEAA4ED54FB1004D9E7A3D,SHA256=B4018F8F249CE087DB46F61A0C2E947248A5B71576F511F0B3650433607BC663,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104855Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-EventLog-Legacy-L1-1-0.dllMD5=B8B7B02C3C66638EC0BDF49BCF04A680,SHA256=5D1103E89199731DFFF7BF89D7F6484C038D47CC04F730CD5233EDE488272E6A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104854Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-Provider-L1-1-0.dllMD5=FEAA05CE6CCB92AA7B2A2C58C049891A,SHA256=31A4AE262E179DF4CA406E1AF90F651935657BB5FD990C675C67E37D5B834CFE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104853Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-Legacy-L1-1-0.dllMD5=88450242D5350529CC8E46FD9C3F3B7B,SHA256=312B6BFC89B551F2C4E8FEDAB316DBE01F190CD5E67091AAFB0E6F67616DC745,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104852Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-Controller-L1-1-0.dllMD5=00A27A81EAAE90C9CED7063013877357,SHA256=DC4EE086FC046E1D7A291EA3B8B13E77B7A252B5C283B8F6C9CEC729070B7822,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104851Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-eventing-consumer-l1-1-0.dllMD5=61958A4BE8F944BAFB29DF8009541FCD,SHA256=3B7CB5622BEAC7D633A84EE2F7336C8DE1D3D1AA10577D98020081AB67761FAD,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104850Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dllMD5=8500E093D6B36DF1AF271F6EB34227CA,SHA256=99E2CD36104D3EFD4DEC88AD0F4BED1FD1BBFA97CC4FB29DB7F7136290DD6B70,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104849Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-devices-config-L1-1-1.dllMD5=5A03B636125C21AB918D2CB04843DBA8,SHA256=C914CD6FE6C7B16533763BC789EDAF67D7A19C26514C927572051C4379C79FC0,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104848Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-devices-config-L1-1-0.dllMD5=0C61A8D9CF9BBF6D771BEF0FF4A43E23,SHA256=66807B95E13944D52E9A7AA1F1A41E632FAA46F6B48F98451618DB3845622577,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104847Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-xstate-l2-1-0.dllMD5=56A386E38B637FCD96CED04CEFBCF8DE,SHA256=A5BE1E3C71A3A5C8EEF4BFAD9D0BADC97BA47B2B9911CED4BD1B8F65BB8DCB77,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104846Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-xstate-l1-1-0.dllMD5=6A982D13DDB295E59F90FF23EDD2E60F,SHA256=3617DBCADFE370463B4DBB91C1C6222923F16EC362DE29C2CA3AE4E72C9ABB64,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104845Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-wow64-l1-1-0.dllMD5=AE7573E1DC370B9A8FEBCC17A6C82FF8,SHA256=59A473D1AD7C181C89AF00B966CD107F1846CDC526009C4807A1EAE3DCB3731D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104844Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-version-l1-1-0.dllMD5=5CB34501C2D784D31281FD526B0BB963,SHA256=E45B73AF0C35F05B01CADF6BD4F67C1497586F4C4F9A16F0448BA751E16C4596,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104843Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-util-l1-1-0.dllMD5=212DA9E9AD6BB61A3554A4174BA558CF,SHA256=01291D3895EC5BB0E658F91FE1512AADCBB6D8F1154BC6023076554AFA05AC1D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104842Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.478{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-url-l1-1-0.dllMD5=198A08F8150D7575CC207CFFCF67D66C,SHA256=86F6DA0F1D075B7E1678DF71689948FEC334CFB10316FEB40E5107135548F9B4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104841Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-timezone-l1-1-0.dllMD5=4D7C132D9742FFA44248B1BBF32020FB,SHA256=58A65C1938DCDF64D2930B037E9D133A5ACDF46365835782869D3216D3CF2CED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104840Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-threadpool-private-l1-1-0.dllMD5=A9BC53B62CD4B269B8385ADBE0AE808D,SHA256=A30003AB0C020E433CC5296E7E150BB11820395D439062FF7FD6D7F449C4C5B3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104839Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-threadpool-legacy-l1-1-0.dllMD5=CAC86F4298EB2D239410B3338780DC34,SHA256=1D99842180A612D63F1A8B137A9BF0375B7113AAB325916BA4781AB8A7B68E7D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104838Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-threadpool-l1-2-0.dllMD5=D32DDF80AB3F1F96F431E5672DC1F387,SHA256=E2F0F0D46082ED40D042BCCD47F4E917707CF884672C5919116126914FAD4572,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104837Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-sysinfo-l1-2-1.dllMD5=E83097DFE144367FA2231828F9FD89A6,SHA256=69FA978126192DBAB6AF11C9878D9C2BD1FD7E3FC899300244DFA4A1AC7ACA31,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104836Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-sysinfo-l1-2-0.dllMD5=8D842EBFFA7803451A3AC7D6907A6AD9,SHA256=808C22A733B5F6A4E601605DCF4043C9952CEBE825FF2622097FC5B4FACF682A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104835Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-sysinfo-l1-1-0.dllMD5=376E34D4A8F94C94FFF063810717612D,SHA256=5285A11016967E2017A8187882579CBD722371D0B7497B356149FC447160A521,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104834Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-synch-l1-2-0.dllMD5=E19F4FA6A6313F00ADE8AF26649A0BA1,SHA256=386F6CC0C3CE0C904A44A2FDDD11B2E5EA7782B08E69FD961DA5BE3C32BA5C26,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104833Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-synch-l1-1-0.dllMD5=95088E453B41A8B50E7340E6DE9CD09C,SHA256=E4938C16CA5FC7A8C9D87E4201FA2F28992026F5858F36A2A44EA22B5BD0889F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104832Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-stringloader-l1-1-1.dllMD5=FE1D00B19175DE6E9729F709C508DD6B,SHA256=D726F32AEB323F4DEA55D35441D1FF06BF3E212846A6B86D9ADC8F9DD1307B57,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104831Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-stringansi-l1-1-0.dllMD5=43F8D61E2EE0E253B973EFED0B3EBC8D,SHA256=1B9FA225A474D42FF8360141C8BC1EE1E7310958910931AC8E5A213E957700BD,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104830Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-string-obsolete-l1-1-0.dllMD5=92C0A4E592B5D773C562A36CBA4E6E47,SHA256=5191E82E921398310FE9FD333F5CA44E6233358499EDD5B33BF8E9F0C9D3B88E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104829Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-string-l2-1-0.dllMD5=3E1902AF98905F00E62B1EC827EB0FC2,SHA256=503443DBF6E6E481EA1C661109CE17B3D55C4FEA001D77F11CD032BDDF64FD29,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104828Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-string-l1-1-0.dllMD5=D30D4587D051D288D1023DB0D826295A,SHA256=DFE66C8C205C95274565BADB7B3C19043917F6CD07A8DE34CE241EFFF9EA6676,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104827Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-shutdown-l1-1-0.dllMD5=1D8D1283F8279BDDACF8745AEDA3DB2A,SHA256=21BF3432160DD9851CAAC716DF3A41E39428A84BA9B9D3C63CDD300CB6928300,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104826Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-shlwapi-obsolete-l1-1-0.dllMD5=33BEFB60C3DC3E93FCE54A0515100181,SHA256=24B3FA4C5E8AB463BD2CFB704D7BFA7E8429726852EF582F94E44D7691BDD1FB,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104825Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-shlwapi-legacy-l1-1-0.dllMD5=699CDC66AA090D13EFF451F2006944CF,SHA256=6212B2B8CF5533F9DB6E366BBADED7A8D6EAD6667EA6A425B6987102669D8D96,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104824Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-rtlsupport-l1-1-0.dllMD5=F9672F68330CD16B0D1FA3A75B123AE8,SHA256=C5938839A3DFFBFBFEF432D0A95D0773375B4758FC160EDD04383A4B4273A18B,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104823Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-registry-l2-1-0.dllMD5=BBC015F33C0C3C2F9FC58C466BF8A30A,SHA256=1ED3511DC98353CA8E9B22A40C318BBD24484C25C171886B06B22AFD396ACFE8,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104822Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-registry-l1-1-0.dllMD5=D132FADCBF190A1C68070E6D488E67D7,SHA256=E6F51C07641EF931C4F97E5D966242BB96A156A603A7769BEAE0EA61E9E25486,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104821Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-realtime-l1-1-0.dllMD5=792C54B79CA333ABBB51BE66815A98CF,SHA256=1E3B3505560AB3E641C386473A83AA194D94CD5BC6CC4FA718D003D1FF899601,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104820Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-profile-l1-1-0.dllMD5=C4E53285E8C51DCBEFF5098215759D69,SHA256=320A6138FE915BE7E83F4CDC2024531948185C3BFC939CB367A53F1AA74BFB2C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104819Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processtopology-obsolete-l1-1-0.dllMD5=99E3ACC47F10000AE67A577F5893FD5A,SHA256=AD01524D3FDDC25C91292808E7B333B587C902E996E557885E79CC10F9A66214,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104818Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processthreads-l1-1-2.dllMD5=DABFBC1EAB7AEE555F3BAEAF981EC7EB,SHA256=3070505B0B060D9EE9C2B699A518481A22DC15ECAF9603089FCF9EBC022179C3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104817Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.462{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processthreads-l1-1-1.dllMD5=8C5DF20B2E2DE6BA6717A597A951E4F7,SHA256=BE42C78E3F21CD6E74811F27E1B76C4FE8537FB149EF34EA455F22AAA29720ED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104816Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processthreads-l1-1-0.dllMD5=3D0CD1FE610E55E8C151162004A1429F,SHA256=D43535460D9CF2F2D348E9F2027DAF9FC0C0C906D5066E15F86332C839C94651,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104815Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processenvironment-l1-2-0.dllMD5=BB20192D0B22AD2EBBF4960B66D2E164,SHA256=23E758C4F7646AACC2DE8B8930BB272115F726F27E5437DF606E1C2328FA48F4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104814Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-processenvironment-l1-1-0.dllMD5=2CF62C9CF255C15AD1C8B1CCDD9453D6,SHA256=35CDE2048D4EC8D5D02B1CA57B81B8D5F579541EDBAF5DA4485A6323B8C3A805,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104813Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-privateprofile-l1-1-1.dllMD5=FA8EFF9B35BE58F70CD0014DAF108819,SHA256=835F086B0884E8E1689D661657F258FA1E71439672E9F0CC0140D614DAB6FA6F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104812Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-privateprofile-l1-1-0.dllMD5=C8490BC5ACB353CAF140CB12670883A2,SHA256=85F3FE5E802843596F466D479111658B08271E48CC1821EB17E6D299D523C95E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104811Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-namedpipe-l1-1-0.dllMD5=D8F1E545D80C2045881C7F0525558D80,SHA256=0D9C3D6A6DF364F812D370258C1B3D3F97584E9F7D36569D06746EBA1695D368,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104810Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-memory-l1-1-2.dllMD5=9F77AA276A31F36805DF003F9E66BD99,SHA256=26425008D97A2EA8B95AF52BFE47CF5DE1DE9BB3E25DF77123B85C895192D7D6,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104809Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-memory-l1-1-1.dllMD5=728A5655624D5B091E8E216BE90D9EF9,SHA256=A2B17F63065CC760FA9CF5D2950D0E13613997546C90CFA1C094CF32171D49ED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104808Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-memory-l1-1-0.dllMD5=BA6B6729DC95AA60AF31A160E2CB4533,SHA256=AA433713D5D1DB4413E9F5D938C0C452BAE8EB1BF8CD011803464BBD893BBB08,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104807Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-localization-obsolete-l1-2-0.dllMD5=B5727AD79BEBAAB6E6AFA381A28A8E9C,SHA256=C0E101B6BCDDC28A9BA24C7796BBDAAEFC14459E402FD53053F3C23E0D84D040,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104806Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-localization-l1-2-1.dllMD5=FD9B6F1EA88B7167E6EC227A61B90888,SHA256=2FEF21096468EE5C6BFC88971AFDB4CC07F6C4669375561863B85023C15684AF,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104805Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-localization-l1-2-0.dllMD5=C8420A86D981BB6AA0D32001D234639E,SHA256=2E93EA8BB070C07C39B7F042B7D9843C4B74B3D4E69C8E33D89B0574B2D1D43D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104804Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-libraryloader-l1-1-1.dllMD5=787DCDC02E39A27A63B857FF6E819593,SHA256=91A7DEC7B636C00032D122CA04D4B8653B13E1211C54A4184F3955D2398C2E2E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104803Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-libraryloader-l1-1-0.dllMD5=AC90FCC4E819CD2EEED5D09A1FA42BAC,SHA256=2DA68FCBCE619BE5A90501F971467B7A894C6A705659346729E1E4E306EEB7D7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104802Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Core-Kernel32-Private-L1-1-1.dllMD5=E269D033D63A117DA8F3F855B90CCBFD,SHA256=41437C84BF757CC5758BF381600D0DECB00E8F8F56F11765203B7880AC4CDDD0,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104801Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Core-Kernel32-Private-L1-1-0.dllMD5=58B0B7C61F098BD1E73E9C156CB38C64,SHA256=C366B92E7048081C7B336CEAB970BAA20AFDAEE2456820AA38360D1429C27669,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104800Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-kernel32-legacy-l1-1-1.dllMD5=912D93DCBE67A1373D93BACD0174E3ED,SHA256=0B94CB7472E0777AEFC1B3208ADDE41B893B78B3223F515FB86348D3362624C3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104799Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-kernel32-legacy-l1-1-0.dllMD5=8E788763C9CDB6E5D1A313C08F7D621E,SHA256=5604FCC803BE14AD10C7A2372FB19BC80D43AD850109A670676982A4EC961473,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104798Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-io-l1-1-1.dllMD5=DC7E345A08B64DDD90906151E1D566E9,SHA256=ABDC082DAA40FCAF14E4E554DF23CFC48533F5A2157BD540BFEC49EB8E31E403,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104797Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-io-l1-1-0.dllMD5=A4381D04E233B96B657262DE9B31594C,SHA256=17BE2709D85E6B922BDF5D357FB4CD9416234F8E6685226F5EC776E8B3B5A678,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104796Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-interlocked-l1-1-0.dllMD5=39646EB20F4366691E3EFF958C99D1D4,SHA256=262D2C2EBAFFA4276F54B05A5A1DA125CC9DCCAF76EAAD3AAF7B23D54EC33C8E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104795Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dllMD5=0C5DE8F3B6CC9B44ED0A0556A02F4867,SHA256=D08261783A1749B08F7423923B00FD77E3B44265889B1F550A64239586BC8FC7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104794Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-heap-l1-1-0.dllMD5=51EBE577149EABD170684C2668F967ED,SHA256=0091D6C33047D8EF6E0F09E049DF2CABA5EE6B4F5B1870E0A369D3BF6DB72330,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104793Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-handle-l1-1-0.dllMD5=F83CB23123F3E4885547ED29F2BD2360,SHA256=495A9EC7C50D6D72F209E1F69C9B0C292D8D32FBE79FE675128786F8E351B988,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104792Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-file-l2-1-1.dllMD5=8B79E85DB9AA6D00794E5151455951BB,SHA256=EE600140599138132439FA9FB9FA6B028A9BF2A206A856CCB1106EFF45459C13,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104791Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.447{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\API-MS-Win-core-file-l2-1-0.dllMD5=455C1AB890C154076E0E23A42F10B6F5,SHA256=DB95D8AA71A8E0A54852C1A83E42267C72E26F2A111AD41146096BF26825FF62,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104790Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-file-l1-2-1.dllMD5=A9808572063E5A5649EA59F8B40FC7A8,SHA256=D4FD5081924D4B544188A687BD37127E0A38AF310E77C55F6EC22896B95B3C9C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104789Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-file-l1-2-0.dllMD5=4438E1D7952A77B7F71FF45EF821814F,SHA256=1C4FA5120E310E49C8112ACB6E594DB2F581AE4B6BA6241EEA4301E0E373959F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104788Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-file-l1-1-0.dllMD5=FF5C179E19923B65E650B11283250D50,SHA256=CF84455BC2AADF2960F0AE4D3691BF3032F412578CB2730A27848C6B26D00225,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104787Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-fibers-l1-1-1.dllMD5=A263189D905386A2A91CD2EB39D3365D,SHA256=7392027920D102DBE4C2C15590CC471063D6B1456CAA797BB71F8973C60B47FC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104786Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-fibers-l1-1-0.dllMD5=A1827E232474C845B7A495D1A4CA6169,SHA256=A95088251923F1233CA4F5675457D6D6B2A1601734D4B5451420298491864746,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104785Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-errorhandling-l1-1-1.dllMD5=E98BCC3FA25D6DB36D50786EF08DBADD,SHA256=7BDA00F42BE64BCC1022EC3000FE2582CDF4CC89083D868ACA9DCE982C98C52C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104784Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-errorhandling-l1-1-0.dllMD5=14E8A42D84E459F617344438903680EE,SHA256=1FCB6E1908C13B5184373E83B3C13FCF96B55E4FBBC8AAF4D6E9DA604DB75848,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104783Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-delayload-l1-1-0.dllMD5=762D2E52FAFE433C50648FC23D7C3E76,SHA256=53238588E10FFAABA96C751D34181BA04A869A0474757E79D9FE82ABC3DC7CFE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104782Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-debug-l1-1-1.dllMD5=1652E7B742F30832826B48E62485BFC7,SHA256=0362AFCDFB6CA89CDEE0DACEC94A5E45D6910B5337343149007DE2443050D154,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104781Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-debug-l1-1-0.dllMD5=E02F6786930435C736D71E9B6B898773,SHA256=4C0F43EAC3834878F16175B17427C0195A3213B7CDF9702447667D703AA29B54,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104780Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-datetime-l1-1-1.dllMD5=78876D83AA27E510EC3DC3355D034B92,SHA256=44A696C4626AF85EA565D651D7FAF5E21B6EB0C6EE47EE93419D8A7BAD565278,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104779Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-datetime-l1-1-0.dllMD5=CF9560A4450AC70C51866581802AE8CC,SHA256=A7A23DC37F028D38D2836CE881FCFF1FD066538588B207BBBCC3B1AB96E3AB62,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104778Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-console-l1-1-0.dllMD5=893E267BD0B91FADAC2A2BAE70FD0400,SHA256=17D17AC0383117E9A14D7687ECAA3B27AF1C71B89687A5C3E5B8761B2E64EDFC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104777Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-comm-l1-1-0.dllMD5=C7EC73197892D7F63059C10D19BD5D90,SHA256=768E17ED08111FD22BAAC8FAC00C7DD87F0E57FEFCDAC58CE04B868528B2FDFC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104776Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-core-com-l1-1-0.dllMD5=08A5A3129DCB52F3C4E51EE3C4A827E7,SHA256=3C6549832275052BCC2234CC4433D95407800ED65359F5147C4762EE0C71F712,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023104775Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:32:26.432{AD5E2759-AA37-6196-70C7-09000000F101}3132WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\874842AE-5D7E-4FC5-A109-C42139BD6D96\api-ms-win-base-util-l1-1-0.dllMD5=29CD6DDC6BADE9098B9A4402C6336D62,SHA256=B97C475AA8241C9B674E8C51C387AFAAA7977B036D9E2F7FAFB6CACC11D985BE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 11241100x800000000000000023105155Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-eventing-consumer-l1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105154Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105153Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-devices-config-L1-1-1.dll2021-11-18 19:33:14.992 11241100x800000000000000023105152Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-devices-config-L1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105151Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-xstate-l2-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105150Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-xstate-l1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105149Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-wow64-l1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105148Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-version-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105147Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-util-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105146Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-url-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105145Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-timezone-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105144Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-threadpool-private-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105143Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-threadpool-legacy-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105142Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-threadpool-l1-2-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105141Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-sysinfo-l1-2-1.dll2021-11-18 19:33:14.977 11241100x800000000000000023105140Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-sysinfo-l1-2-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105139Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-sysinfo-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105138Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-synch-l1-2-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105137Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-synch-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105136Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-stringloader-l1-1-1.dll2021-11-18 19:33:14.977 11241100x800000000000000023105135Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-stringansi-l1-1-0.dll2021-11-18 19:33:14.977 11241100x800000000000000023105134Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.977{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-string-obsolete-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105133Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-string-l2-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105132Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-string-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105131Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-shutdown-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105130Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105129Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-shlwapi-legacy-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105128Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-rtlsupport-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105127Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-registry-l2-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105126Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-registry-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105125Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-realtime-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105124Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-profile-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105123Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processtopology-obsolete-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105122Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processthreads-l1-1-2.dll2021-11-18 19:33:14.961 11241100x800000000000000023105121Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processthreads-l1-1-1.dll2021-11-18 19:33:14.961 11241100x800000000000000023105120Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processthreads-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105119Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processenvironment-l1-2-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105118Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processenvironment-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105117Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-privateprofile-l1-1-1.dll2021-11-18 19:33:14.961 11241100x800000000000000023105116Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-privateprofile-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105115Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-namedpipe-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105114Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-memory-l1-1-2.dll2021-11-18 19:33:14.961 11241100x800000000000000023105113Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-memory-l1-1-1.dll2021-11-18 19:33:14.961 11241100x800000000000000023105112Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.961{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-memory-l1-1-0.dll2021-11-18 19:33:14.961 11241100x800000000000000023105111Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-localization-obsolete-l1-2-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105110Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-localization-l1-2-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105109Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-localization-l1-2-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105108Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-libraryloader-l1-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105107Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-libraryloader-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105106Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105105Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105104Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-kernel32-legacy-l1-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105103Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-kernel32-legacy-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105102Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-io-l1-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105101Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-io-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105100Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-interlocked-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105099Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105098Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-heap-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105097Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-handle-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105096Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-file-l2-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105095Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-file-l2-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105094Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-file-l1-2-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105093Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-file-l1-2-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105092Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-file-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105091Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-fibers-l1-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105090Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-fibers-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105089Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-errorhandling-l1-1-1.dll2021-11-18 19:33:14.946 11241100x800000000000000023105088Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.946{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-errorhandling-l1-1-0.dll2021-11-18 19:33:14.946 11241100x800000000000000023105087Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-delayload-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105086Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-debug-l1-1-1.dll2021-11-18 19:33:14.930 11241100x800000000000000023105085Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-debug-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105084Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-datetime-l1-1-1.dll2021-11-18 19:33:14.930 11241100x800000000000000023105083Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-datetime-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105082Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-console-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105081Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-comm-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105080Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-com-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105079Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-base-util-l1-1-0.dll2021-11-18 19:33:14.930 11241100x800000000000000023105078Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\WimProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105077Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\VhdProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105076Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\UnattendProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105075Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\TransmogProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105074Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\SmiProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105073Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\ProvProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105072Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\OSProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105071Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\OfflineSetupProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105070Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\MsiProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105069Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\LogProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105068Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.930{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\IntlProvider.dll2021-11-18 19:33:14.930 11241100x800000000000000023105067Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.914{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\ImagingProvider.dll2021-11-18 19:33:14.914 11241100x800000000000000023105066Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.914{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\IBSProvider.dll2021-11-18 19:33:14.914 11241100x800000000000000023105065Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.914{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\GenericProvider.dll2021-11-18 19:33:14.914 11241100x800000000000000023105064Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.914{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\FolderProvider.dll2021-11-18 19:33:14.914 11241100x800000000000000023105063Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.914{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\FfuProvider.dll2021-11-18 19:33:14.914 11241100x800000000000000023105062Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DmiProvider.dll2021-11-18 19:33:14.899 11241100x800000000000000023105061Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismProv.dll2021-11-18 19:33:14.899 11241100x800000000000000023105060Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localEXE2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismHost.exe2021-11-18 19:33:14.899 11241100x800000000000000023105059Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismCorePS.dll2021-11-18 19:33:14.899 11241100x800000000000000023105058Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismCore.dll2021-11-18 19:33:14.899 11241100x800000000000000023105057Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\CompatProvider.dll2021-11-18 19:33:14.899 11241100x800000000000000023105056Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\CbsProvider.dll2021-11-18 19:33:14.899 11241100x800000000000000023105055Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\AssocProvider.dll2021-11-18 19:33:14.899 11241100x800000000000000023105054Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.899{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\AppxProvider.dll2021-11-18 19:33:14.899 10341000x800000000000000023105053Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:14.881{AD5E2759-5433-6143-0C00-00000000F101}7321852C:\Windows\system32\svchost.exe{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5126|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000023105052Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:14.881{AD5E2759-A1BE-6168-4461-04000000F101}57005728C:\Windows\system32\conhost.exe{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000023105047Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:14.865{AD5E2759-A1AF-6168-1D61-04000000F101}2172928C:\Windows\system32\csrss.exe{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000023105046Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:14.865{AD5E2759-A1BE-6168-4361-04000000F101}56885856C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\2a6ccbaba5690e5b3fec3bf707022bdb\System.ni.dll+384146|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\2a6ccbaba5690e5b3fec3bf707022bdb\System.ni.dll+2c4809|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\2a6ccbaba5690e5b3fec3bf707022bdb\System.ni.dll+2c4179|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+de4d0027(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd953480(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd9530bb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+de41b3e9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd91002d(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd973a9f(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd955aae(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd955aae(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd95593f(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd94665f(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd953ba1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd953713(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd953480(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd9530bb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+de41b3e9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd938366(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\0784610d68cd6b36e46150702bf69c35\System.Management.Automation.ni.dll+dd9378d8(wow64) 154100x800000000000000023105045Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:14.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\System32\Dism.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Image Servicing UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationDISM.EXE"C:\Windows\system32\Dism.exe" /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quietC:\Users\Administrator\Desktop\WIN-HOST-874\Administrator{AD5E2759-A1B1-6168-DD52-B32300000000}0x23b352dd2HighMD5=DD0DC0C490755CEA51413D940B31CF0C,SHA256=71C182B3550A7DCC61B56C2D7E363673574CD03000A5081C0A228D775ECAC133,IMPHASH=07D06C9BFC08891808D6DE5FCD00BC8A{AD5E2759-A1BE-6168-4361-04000000F101}5688C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" 10341000x800000000000000023105175Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}15366108C:\Windows\system32\Dism.exe{AD5E2759-AA7B-6196-7FC7-09000000F101}5732C:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\dismhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\Dism\DismCore.dll+273f6|C:\Windows\System32\Dism\DismCore.dll+8eaa|C:\Windows\System32\Dism\DismCore.dll+58d4|C:\Windows\system32\Dism.exe+cd60|C:\Windows\system32\Dism.exe+4bd3|C:\Windows\system32\Dism.exe+3c84|C:\Windows\system32\Dism.exe+26b9|C:\Windows\system32\Dism.exe+1db1|C:\Windows\system32\Dism.exe+21fed|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000023105174Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:15.017{AD5E2759-AA7B-6196-7FC7-09000000F101}5732C:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismHost.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Host Servicing ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationDismHost.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\dismhost.exe {36D844C9-A09B-41D4-9747-DDFC80E10E75}C:\Users\Administrator\Desktop\WIN-HOST-874\Administrator{AD5E2759-A1B1-6168-DD52-B32300000000}0x23b352dd2HighMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\System32\Dism.exe"C:\Windows\system32\Dism.exe" /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quiet 11241100x800000000000000023105173Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-winsvc-l1-1-0.dll2021-11-18 19:33:15.008 11241100x800000000000000023105172Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-private-l1-1-1.dll2021-11-18 19:33:15.008 11241100x800000000000000023105171Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-private-l1-1-0.dll2021-11-18 19:33:15.008 11241100x800000000000000023105170Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-management-l2-1-0.dll2021-11-18 19:33:15.008 11241100x800000000000000023105169Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-management-l1-1-0.dll2021-11-18 19:33:15.008 11241100x800000000000000023105168Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-core-l1-1-1.dll2021-11-18 19:33:15.008 11241100x800000000000000023105167Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-core-l1-1-0.dll2021-11-18 19:33:15.008 11241100x800000000000000023105166Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-security-sddl-l1-1-0.dll2021-11-18 19:33:15.008 11241100x800000000000000023105165Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:15.008{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-security-provider-L1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105164Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-security-lsapolicy-l1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105163Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Security-Lsalookup-L2-1-1.dll2021-11-18 19:33:14.992 11241100x800000000000000023105162Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Security-Lsalookup-L2-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105161Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-security-cryptoapi-l1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105160Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-security-base-l1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105159Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-EventLog-Legacy-L1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105158Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-Provider-L1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105157Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-Legacy-L1-1-0.dll2021-11-18 19:33:14.992 11241100x800000000000000023105156Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:14.992{AD5E2759-AA7A-6196-7EC7-09000000F101}1536C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-Controller-L1-1-0.dll2021-11-18 19:33:14.992 23542300x800000000000000023105338Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.927{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\WimProvider.dllMD5=1B0C7DFB2240BA004B37904073624DB3,SHA256=F2C7DB522DDE968EDF49B03BC10978AAC4C42C745CA4A474627E8CEBBCEBB00A,IMPHASH=20D31D66F56B810094B1AA564C92009Dtruefalse - insufficient disk space 23542300x800000000000000023105337Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.927{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\VhdProvider.dllMD5=F37C8F5BF852151D9BF085687A8DEC6D,SHA256=6CDFC95C2F2ED3695D5EE8CF4367A6C7FB5707DA3C234CEE8FA8C1BBDE426DE7,IMPHASH=3CA997A1A0BD38B850B18DAED5E948DEtruefalse - insufficient disk space 23542300x800000000000000023105336Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.909{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\UnattendProvider.dllMD5=3DB4777B76FC1973A61754FAEC348981,SHA256=29A4C7379E5A0A7532C90B5ACE0DD99AB5311D03CC0BA6A4BCFB410D7D8B01AE,IMPHASH=4FA75E8720452554D61C8AC5FD64C43Ftruefalse - insufficient disk space 23542300x800000000000000023105335Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.909{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\TransmogProvider.dllMD5=5E82E2B7CFF045C7CDA8E33EAB186402,SHA256=0038B82E999C3DEF3980D39A8CAED9EA6B52A4FC9EF58BF3B3F5FC91F7748112,IMPHASH=7746C0E3C7D3763C5F13C90D4934087Btruefalse - insufficient disk space 23542300x800000000000000023105334Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.909{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\SmiProvider.dllMD5=C5C7A9E3121B91E51ECFBA6FB2985044,SHA256=FB519B9EEF4C3344D58C768BD3AD7ADCB0677EA7B998056B6A13620CB9E61412,IMPHASH=03C38376DA7CCE75E82EECACADA0EA03truefalse - insufficient disk space 23542300x800000000000000023105333Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.893{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\ProvProvider.dllMD5=5077063311C5708318C5FA3E255011ED,SHA256=97FA95102B6ACF00C70F140EE9FA4A73A6BE7C03E0F0D99AE58DB5E492CD0ECA,IMPHASH=D8DD764BFC0F1D9E403714D169018B83truefalse - insufficient disk space 23542300x800000000000000023105332Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.893{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\OSProvider.dllMD5=4868187A2F176074DB7F35E356F74D4F,SHA256=84C8C4C67C808871A278254304D985533F67D44391840F43674FC829014E1B60,IMPHASH=82A4D833A82D441391A9AA3027199337truefalse - insufficient disk space 23542300x800000000000000023105331Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.893{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\OfflineSetupProvider.dllMD5=86B7E8438B1125C479FD275B1BDDB9A7,SHA256=47FAF8671B25A30D7BCC47AD35926D70DB633A181FA6C276479B4408A526E63E,IMPHASH=B8B4A188EFC4F12D33591C6D319B6F12truefalse - insufficient disk space 23542300x800000000000000023105330Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.893{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\MsiProvider.dllMD5=EA19239A85416A488360FA564D312402,SHA256=F21591336CD1A24EE941827620405FA34414C1C349216B4B8083ECD1FFF17C29,IMPHASH=33E1132923056DDEFB0521726DA5B987truefalse - insufficient disk space 23542300x800000000000000023105329Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.893{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\LogProvider.dllMD5=F7DB4F104DBB56DF5A156E7329E80112,SHA256=7C67EFAF44D1413576B4575B1A4C975BCB10B64BEF13E6756E895D4DB9E61AA2,IMPHASH=FB695172E8A76C56E97CE435F8ED0220truefalse - insufficient disk space 23542300x800000000000000023105328Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\IntlProvider.dllMD5=0082903881275179642AE83EFA720310,SHA256=7CCF1625E6FBE4DB16F12AC037E4236A3EF269DEE47A157C68374C867941F9E8,IMPHASH=CFB81BC5FF922F23D605A653700FE666truefalse - insufficient disk space 23542300x800000000000000023105327Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\ImagingProvider.dllMD5=EEB4AA36BAD26A2C6216A1FF3439B58C,SHA256=44A6679425039DC870C297294C4B3323F6FA9DE5C7D16D7D0AB7E1254AFC75D3,IMPHASH=0264D9B4BFE54732ADF0E29BC73BF280truefalse - insufficient disk space 23542300x800000000000000023105326Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\IBSProvider.dllMD5=11DE34FCDB75E79A920D3B491F3E7BF0,SHA256=6B7C7AD8B1AD522B27B2CC5E4F76F56ADE4495D7D46CE4F997A68954F072AF17,IMPHASH=C755896FA14213058E34639A28868FBCtruefalse - insufficient disk space 23542300x800000000000000023105325Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\GenericProvider.dllMD5=397ED660129D40927A27B75A4B8FAE2E,SHA256=EAFCECFE911DABB4531E1331DDF2E119DCBB6B7A887D70BDE737EA76BE10EB74,IMPHASH=F55EE75573C110804DE5E50ACEEC1B06truefalse - insufficient disk space 23542300x800000000000000023105324Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\FolderProvider.dllMD5=6428B4D0C26DB23E9478F039891CD5C9,SHA256=55126BB099785C2F9CD32A30991082C47D62C8231D570A9D8A6F3CC599B25EE1,IMPHASH=B2CC5EDD42A866F7CB6CAE42DB969187truefalse - insufficient disk space 23542300x800000000000000023105323Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\FfuProvider.dllMD5=E27BC7F808E72F08372BA3C40B4B6344,SHA256=927B194432046C0D2ADF7C7B71E4BE85602C4D00A5D6EDA9F9DB9924E1C3447A,IMPHASH=8580AF5C1871319D05329DB2E96A8146truefalse - insufficient disk space 23542300x800000000000000023105322Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\WimProvider.dll.muiMD5=CC3B15540DDB521A300BAFF0BF4F902E,SHA256=33C06CC037DF1EBB72A15BCC2E09BC89DFEF7DD94441C650FD3D0C833122002A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105321Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\VhdProvider.dll.muiMD5=10536C56F02E68EBD13D0B2CE8665C6A,SHA256=06C3B71D251A8DD47D02EDBFBE84E0B6B1D67956DE4D3996031434CBAD728929,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105320Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\UnattendProvider.dll.muiMD5=B7E3676672BE6851EA13ADD879C2945E,SHA256=2D2D82EE842CD346B58DCAFAE6FEC46D491E0D15CFBE0D8964A4AB7F18C5AAB9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105319Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.878{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\TransmogProvider.dll.muiMD5=D5D596B1102DA565C2ED1FAAC170E758,SHA256=B5DBB36E947FD64AAF22C53F0A9634C7D72D4CC270C055B67E020920BF806909,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105318Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\SmiProvider.dll.muiMD5=CAD746ED5AF63E7FC49ED4A5A3984629,SHA256=016C6071B04E6D7E12AD9B8A85C002320331E01ED62922C573A1AC43BA0DD919,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105317Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\ProvProvider.dll.muiMD5=70AFEC86B6CF677BF8D3C713CA3281FB,SHA256=C8579EC95A51EB663FFC6145F0998C2F1930A6B8146C84C0A9094BCA4E5195A7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105316Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\OSProvider.dll.muiMD5=A464DFEDEA8520616AA9B2ACD166A77F,SHA256=54E985CFF256CEBE82E9EF3E814A5FDA9FF730BCB50265E9BA78DE65A4DE3F42,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105315Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\OfflineSetupProvider.dll.muiMD5=CED788DBD9D13D0490B2F642B0B051F6,SHA256=D5DBC0A52B598800EE14569859383525950B865F4816E47E2E73F79AA1C32A09,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105314Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\MsiProvider.dll.muiMD5=5AE9ABD6BB469F3AD7B3A4CCD40974BF,SHA256=C2CE66F2F218890AA76F8BAB68B4C0FDCED0688E694F912F3A5BFABFA6CDB5E7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105313Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\LogProvider.dll.muiMD5=0D4519BC8EB58A006E4A5EB993C0DCCF,SHA256=DAFFE67521F9B4657FBFEF9585234CB39293F9B866C0D97D66F675037515BB51,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105312Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\IntlProvider.dll.muiMD5=16ACB74928BC55FD4AAC316F3B92E1D7,SHA256=17CB486CADB679C75A27BA6C76E2FE714F4B8DA845E6F795759517D6734F0BC9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105311Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\ImagingProvider.dll.muiMD5=26F5BBF8D6EE90B4F47C18E93D1087FB,SHA256=F41738FEF7140176447ECF371B1117A485E48BA6F3E9AFAA8C4F883ABFAE62DA,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105310Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\IBSProvider.dll.muiMD5=0B09FE334215A8E736B2CF08A50D5204,SHA256=DCE9AD3B79F91BEBEDDFCD9E03F1557CB7C6114AC906081E9E046F807093CDF1,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105309Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\GenericProvider.dll.muiMD5=956B8B45B92321C0D5975EE9A6C5B773,SHA256=578541D71466CF61EF399023B34EDFCBD915142BE856534AD4D17D25E7CC9F3D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105308Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\FolderProvider.dll.muiMD5=DC4E4C2800DC6D98F7893044A21D246B,SHA256=8B4CE62F4E4294E701193C7AE393EB5EB29AA45932D376CB1A03728A140096AE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105307Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\FfuProvider.dll.muiMD5=5ECAD70AC2B3A95CBB42D6FE67D2F726,SHA256=C210389DBB9B7B4A802E4B0C3C708B6F55B086564A01E19CFB183B6AF916C30A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105306Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\DmiProvider.dll.muiMD5=38C2A1560C340537C3AE0CE04BDF7EAA,SHA256=52B06DFD85FB5AB1DCE2BE665CA144B1AE6658F518D1623D9B44C347C482B064,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105305Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\DismProv.dll.muiMD5=BD7B77B3EE9A12FF3F5446ECDF80B5C6,SHA256=B972A0B2C4682E9074441B481BD886DE19B8DB3DBA401B88E980B154C14D5A7E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105304Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\DismCore.dll.muiMD5=C901FF639EDFBBE710D6E5882F07CD24,SHA256=9BDA61D23DC50F9AFA82DA94B06B7B9C8229D5ED666D2F5270DAE13100815C27,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105303Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\CompatProvider.dll.muiMD5=A2A344CB32B6835744A36D877C952665,SHA256=A74D765B796638A921C4810D1712A08F7A37C9BA9E91F4DFDCB9727611C3D18D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105302Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\CbsProvider.dll.muiMD5=179B34BE97A383AF3E757031E7DA964B,SHA256=ABD3824664D1336EE849D89BA178606CC1B1E23E173752D8093F34A5580FA8F4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105301Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\AssocProvider.dll.muiMD5=386FE7AC95738A0CB6D25DEA662991F1,SHA256=22DC7317108A528BA92C853330598F628B93FFF27CAC34C2F501B806A75261D9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105300Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\en-US\AppxProvider.dll.muiMD5=9FF5081115C2C21D9F85AF7EE6D2CC63,SHA256=107B10A8C1426F1C0D703F06832D740A4CFDCAA596FA0EA147A32A736A7A2A4D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105299Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DmiProvider.dllMD5=FC76385FF00D4A93618D842B41716D8D,SHA256=BBD49A49CFFA8411FFA91B02541F5F3B5333FD9055BC129DDD3B36EB005C34D9,IMPHASH=062B279D8ED4374A0CD0C84620F4BE4Etruefalse - insufficient disk space 23542300x800000000000000023105298Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.862{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismProv.dllMD5=8C7D97E22045AE402EA896F514CEED81,SHA256=76D3202E11BA22D277532A14CAE60E596975C0D8C34C7BE154F453EB1F7C37EF,IMPHASH=0247CB1C8FD55E43A448E359883057DBtruefalse - insufficient disk space 23542300x800000000000000023105297Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.846{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismHost.exeMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424truefalse - insufficient disk space 23542300x800000000000000023105296Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.846{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismCorePS.dllMD5=FB88731B484D1FF4AFF5DB75A20799FA,SHA256=EA155388211E0C3CEF2C99BD5F341C9F93F1ECDA6F21096DB6F9DB2110686A52,IMPHASH=65E10DCEA11F7117C161DC7557B87689truefalse - insufficient disk space 23542300x800000000000000023105295Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.846{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\DismCore.dllMD5=F1AB58CACD95921A04225222D03CDEA0,SHA256=EDE89F377FD46F95639413411CDA072D9FF63E72A399B26AB4870094F145091B,IMPHASH=B7B56C790C8AB7134B0680D8DFE46658truefalse - insufficient disk space 23542300x800000000000000023105294Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.846{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\CompatProvider.dllMD5=E5C1D020198EBEC1D5ABA640C9A600D0,SHA256=A80FD2846E05AB491BDAAFCE8854A04549A852066B82B90D757D9B6A44ADA8C8,IMPHASH=2CDD615C09EED7B572606B2A0C0EFD2Ftruefalse - insufficient disk space 23542300x800000000000000023105293Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.846{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\CbsProvider.dllMD5=D4A64C7C50D0C6BE9F8770177E2264BF,SHA256=E6505F9DBE17DF9E7E52B5FE1720E1F6482B25D262A47A320CF438C5FD5A5797,IMPHASH=99D5DC4FF67AB12670853DD4E32E8358truefalse - insufficient disk space 23542300x800000000000000023105292Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\AssocProvider.dllMD5=56CB83B3454882509791FBA62832BC87,SHA256=5B01524CC03B6EB58CC9E0FF479014EAF89EE7FDE2791BFF871BC90274D200AC,IMPHASH=83F73507B4613B09C6FA825535D8A81Etruefalse - insufficient disk space 23542300x800000000000000023105291Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\AppxProvider.dllMD5=8F6792DF9EC54934B76A68B1D7B66ECA,SHA256=E57CB2D5CEC5E1354F4E31CD08ADA02FCAA0E2DEA4B28C8F61683BFA3E875C05,IMPHASH=F1558CACACA712554EBD5926B4B3FE52truefalse - insufficient disk space 23542300x800000000000000023105290Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-winsvc-l1-1-0.dllMD5=09934F0F7227B9489D117C26EC20CD14,SHA256=CBE408A0AFF90986A6A7DDF022F96302B4FADD08A0C3C166CAC7A64D6ABF041D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105289Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-private-l1-1-1.dllMD5=484ED248F1A72C6E4E6F6C3F5A3339ED,SHA256=00E14515FE6FEBBF3C2CFC89A6F1A3D6F48B3E7A5EB08D50DADF69CE3F34CC47,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105288Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-private-l1-1-0.dllMD5=FEBE55EA884F3C1EE45ADE2734AA6BE6,SHA256=CD51DF334A600117133C9C8100DDE766D980456988FD333A40BE5A81C8092340,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105287Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-management-l2-1-0.dllMD5=0D45D811001E0A7683A2B7CA8A883874,SHA256=F44E2A85D7507159AE115C85C3497C57BE4ECB2D6ADDB30A534110266D56F92F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105286Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-management-l1-1-0.dllMD5=C36912B3A28B06F5BB24FE9BE49DA4D3,SHA256=D737A832C0D595E8E52846C2D748B911D7155E372F43FBB10513CFDE0BBF83B7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105285Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.831{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-core-l1-1-1.dllMD5=A86D518BCF3970C17A1768792FDF37FF,SHA256=AB5CC1B14D6BB708B5C87C2622DA886E2119A6997E08108CCE36080385DAEE71,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105284Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-service-core-l1-1-0.dllMD5=A329C75641638E2FFA11087F614FD4C1,SHA256=5071AA303D436407D195EF37889F018BE7E350DA5E690793587458D4C6D308DB,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105283Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-security-sddl-l1-1-0.dllMD5=C6C6C3E4D7CFA93246362901750A94D9,SHA256=6E274ABE823EF8B30629A99D9F942794C9FE6D003021A0C5085B49A7D8611DDE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105282Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-security-provider-L1-1-0.dllMD5=207B5716605CA4850629F3E2FFFA07BB,SHA256=BE6E6284F69C76BE6366EA8D44D85BDBAB6A71DD42E8B5575CFDF671AD58DCA2,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105281Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-security-lsapolicy-l1-1-0.dllMD5=FE7AD7265E296947172B8C491E8109D2,SHA256=4D231AC65F0F54BFF45CACFFE7DF3109CF87F78D14960EC8F03654E605AC8ABF,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105280Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Security-Lsalookup-L2-1-1.dllMD5=EBD6475839F5C99FB8855A80E0FC2AF1,SHA256=F519C7AA6930DAC83A3045CEEE42F64F26FFC54254D5ABD1B0F7D99C47569A30,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105279Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Security-Lsalookup-L2-1-0.dllMD5=AC284A6251F5D26633AF48D918D09628,SHA256=F7A34B793AACF75DA4EAE843B6088C0BAAA8B835EA5F6A65E72EBD9A1479C8A8,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105278Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-security-cryptoapi-l1-1-0.dllMD5=DE0A49D4B2E9A5FA6762BD191C622B32,SHA256=AB12FEAF15CB313812B01AFE1198B62E72F7702D140830ABAD2CFB6251E82A7C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105277Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-security-base-l1-1-0.dllMD5=DC4B661366FEAA4ED54FB1004D9E7A3D,SHA256=B4018F8F249CE087DB46F61A0C2E947248A5B71576F511F0B3650433607BC663,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105276Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-EventLog-Legacy-L1-1-0.dllMD5=B8B7B02C3C66638EC0BDF49BCF04A680,SHA256=5D1103E89199731DFFF7BF89D7F6484C038D47CC04F730CD5233EDE488272E6A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105275Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-Provider-L1-1-0.dllMD5=FEAA05CE6CCB92AA7B2A2C58C049891A,SHA256=31A4AE262E179DF4CA406E1AF90F651935657BB5FD990C675C67E37D5B834CFE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105274Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-Legacy-L1-1-0.dllMD5=88450242D5350529CC8E46FD9C3F3B7B,SHA256=312B6BFC89B551F2C4E8FEDAB316DBE01F190CD5E67091AAFB0E6F67616DC745,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105273Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-Controller-L1-1-0.dllMD5=00A27A81EAAE90C9CED7063013877357,SHA256=DC4EE086FC046E1D7A291EA3B8B13E77B7A252B5C283B8F6C9CEC729070B7822,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105272Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-eventing-consumer-l1-1-0.dllMD5=61958A4BE8F944BAFB29DF8009541FCD,SHA256=3B7CB5622BEAC7D633A84EE2F7336C8DE1D3D1AA10577D98020081AB67761FAD,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105271Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dllMD5=8500E093D6B36DF1AF271F6EB34227CA,SHA256=99E2CD36104D3EFD4DEC88AD0F4BED1FD1BBFA97CC4FB29DB7F7136290DD6B70,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105270Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-devices-config-L1-1-1.dllMD5=5A03B636125C21AB918D2CB04843DBA8,SHA256=C914CD6FE6C7B16533763BC789EDAF67D7A19C26514C927572051C4379C79FC0,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105269Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-devices-config-L1-1-0.dllMD5=0C61A8D9CF9BBF6D771BEF0FF4A43E23,SHA256=66807B95E13944D52E9A7AA1F1A41E632FAA46F6B48F98451618DB3845622577,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105268Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-xstate-l2-1-0.dllMD5=56A386E38B637FCD96CED04CEFBCF8DE,SHA256=A5BE1E3C71A3A5C8EEF4BFAD9D0BADC97BA47B2B9911CED4BD1B8F65BB8DCB77,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105267Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-xstate-l1-1-0.dllMD5=6A982D13DDB295E59F90FF23EDD2E60F,SHA256=3617DBCADFE370463B4DBB91C1C6222923F16EC362DE29C2CA3AE4E72C9ABB64,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105266Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-wow64-l1-1-0.dllMD5=AE7573E1DC370B9A8FEBCC17A6C82FF8,SHA256=59A473D1AD7C181C89AF00B966CD107F1846CDC526009C4807A1EAE3DCB3731D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105265Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-version-l1-1-0.dllMD5=5CB34501C2D784D31281FD526B0BB963,SHA256=E45B73AF0C35F05B01CADF6BD4F67C1497586F4C4F9A16F0448BA751E16C4596,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105264Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-util-l1-1-0.dllMD5=212DA9E9AD6BB61A3554A4174BA558CF,SHA256=01291D3895EC5BB0E658F91FE1512AADCBB6D8F1154BC6023076554AFA05AC1D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105263Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-url-l1-1-0.dllMD5=198A08F8150D7575CC207CFFCF67D66C,SHA256=86F6DA0F1D075B7E1678DF71689948FEC334CFB10316FEB40E5107135548F9B4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105262Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.815{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-timezone-l1-1-0.dllMD5=4D7C132D9742FFA44248B1BBF32020FB,SHA256=58A65C1938DCDF64D2930B037E9D133A5ACDF46365835782869D3216D3CF2CED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105261Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-threadpool-private-l1-1-0.dllMD5=A9BC53B62CD4B269B8385ADBE0AE808D,SHA256=A30003AB0C020E433CC5296E7E150BB11820395D439062FF7FD6D7F449C4C5B3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105260Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-threadpool-legacy-l1-1-0.dllMD5=CAC86F4298EB2D239410B3338780DC34,SHA256=1D99842180A612D63F1A8B137A9BF0375B7113AAB325916BA4781AB8A7B68E7D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105259Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-threadpool-l1-2-0.dllMD5=D32DDF80AB3F1F96F431E5672DC1F387,SHA256=E2F0F0D46082ED40D042BCCD47F4E917707CF884672C5919116126914FAD4572,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105258Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-sysinfo-l1-2-1.dllMD5=E83097DFE144367FA2231828F9FD89A6,SHA256=69FA978126192DBAB6AF11C9878D9C2BD1FD7E3FC899300244DFA4A1AC7ACA31,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105257Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-sysinfo-l1-2-0.dllMD5=8D842EBFFA7803451A3AC7D6907A6AD9,SHA256=808C22A733B5F6A4E601605DCF4043C9952CEBE825FF2622097FC5B4FACF682A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105256Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-sysinfo-l1-1-0.dllMD5=376E34D4A8F94C94FFF063810717612D,SHA256=5285A11016967E2017A8187882579CBD722371D0B7497B356149FC447160A521,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105255Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-synch-l1-2-0.dllMD5=E19F4FA6A6313F00ADE8AF26649A0BA1,SHA256=386F6CC0C3CE0C904A44A2FDDD11B2E5EA7782B08E69FD961DA5BE3C32BA5C26,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105254Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-synch-l1-1-0.dllMD5=95088E453B41A8B50E7340E6DE9CD09C,SHA256=E4938C16CA5FC7A8C9D87E4201FA2F28992026F5858F36A2A44EA22B5BD0889F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105253Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-stringloader-l1-1-1.dllMD5=FE1D00B19175DE6E9729F709C508DD6B,SHA256=D726F32AEB323F4DEA55D35441D1FF06BF3E212846A6B86D9ADC8F9DD1307B57,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105252Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-stringansi-l1-1-0.dllMD5=43F8D61E2EE0E253B973EFED0B3EBC8D,SHA256=1B9FA225A474D42FF8360141C8BC1EE1E7310958910931AC8E5A213E957700BD,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105251Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-string-obsolete-l1-1-0.dllMD5=92C0A4E592B5D773C562A36CBA4E6E47,SHA256=5191E82E921398310FE9FD333F5CA44E6233358499EDD5B33BF8E9F0C9D3B88E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105250Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-string-l2-1-0.dllMD5=3E1902AF98905F00E62B1EC827EB0FC2,SHA256=503443DBF6E6E481EA1C661109CE17B3D55C4FEA001D77F11CD032BDDF64FD29,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105249Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-string-l1-1-0.dllMD5=D30D4587D051D288D1023DB0D826295A,SHA256=DFE66C8C205C95274565BADB7B3C19043917F6CD07A8DE34CE241EFFF9EA6676,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105248Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-shutdown-l1-1-0.dllMD5=1D8D1283F8279BDDACF8745AEDA3DB2A,SHA256=21BF3432160DD9851CAAC716DF3A41E39428A84BA9B9D3C63CDD300CB6928300,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105247Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-shlwapi-obsolete-l1-1-0.dllMD5=33BEFB60C3DC3E93FCE54A0515100181,SHA256=24B3FA4C5E8AB463BD2CFB704D7BFA7E8429726852EF582F94E44D7691BDD1FB,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105246Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-shlwapi-legacy-l1-1-0.dllMD5=699CDC66AA090D13EFF451F2006944CF,SHA256=6212B2B8CF5533F9DB6E366BBADED7A8D6EAD6667EA6A425B6987102669D8D96,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105245Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-rtlsupport-l1-1-0.dllMD5=F9672F68330CD16B0D1FA3A75B123AE8,SHA256=C5938839A3DFFBFBFEF432D0A95D0773375B4758FC160EDD04383A4B4273A18B,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105244Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-registry-l2-1-0.dllMD5=BBC015F33C0C3C2F9FC58C466BF8A30A,SHA256=1ED3511DC98353CA8E9B22A40C318BBD24484C25C171886B06B22AFD396ACFE8,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105243Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-registry-l1-1-0.dllMD5=D132FADCBF190A1C68070E6D488E67D7,SHA256=E6F51C07641EF931C4F97E5D966242BB96A156A603A7769BEAE0EA61E9E25486,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105242Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.799{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-realtime-l1-1-0.dllMD5=792C54B79CA333ABBB51BE66815A98CF,SHA256=1E3B3505560AB3E641C386473A83AA194D94CD5BC6CC4FA718D003D1FF899601,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105241Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-profile-l1-1-0.dllMD5=C4E53285E8C51DCBEFF5098215759D69,SHA256=320A6138FE915BE7E83F4CDC2024531948185C3BFC939CB367A53F1AA74BFB2C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105240Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processtopology-obsolete-l1-1-0.dllMD5=99E3ACC47F10000AE67A577F5893FD5A,SHA256=AD01524D3FDDC25C91292808E7B333B587C902E996E557885E79CC10F9A66214,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105239Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processthreads-l1-1-2.dllMD5=DABFBC1EAB7AEE555F3BAEAF981EC7EB,SHA256=3070505B0B060D9EE9C2B699A518481A22DC15ECAF9603089FCF9EBC022179C3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105238Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processthreads-l1-1-1.dllMD5=8C5DF20B2E2DE6BA6717A597A951E4F7,SHA256=BE42C78E3F21CD6E74811F27E1B76C4FE8537FB149EF34EA455F22AAA29720ED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105237Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processthreads-l1-1-0.dllMD5=3D0CD1FE610E55E8C151162004A1429F,SHA256=D43535460D9CF2F2D348E9F2027DAF9FC0C0C906D5066E15F86332C839C94651,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105236Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processenvironment-l1-2-0.dllMD5=BB20192D0B22AD2EBBF4960B66D2E164,SHA256=23E758C4F7646AACC2DE8B8930BB272115F726F27E5437DF606E1C2328FA48F4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105235Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-processenvironment-l1-1-0.dllMD5=2CF62C9CF255C15AD1C8B1CCDD9453D6,SHA256=35CDE2048D4EC8D5D02B1CA57B81B8D5F579541EDBAF5DA4485A6323B8C3A805,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105234Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-privateprofile-l1-1-1.dllMD5=FA8EFF9B35BE58F70CD0014DAF108819,SHA256=835F086B0884E8E1689D661657F258FA1E71439672E9F0CC0140D614DAB6FA6F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105233Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-privateprofile-l1-1-0.dllMD5=C8490BC5ACB353CAF140CB12670883A2,SHA256=85F3FE5E802843596F466D479111658B08271E48CC1821EB17E6D299D523C95E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105232Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-namedpipe-l1-1-0.dllMD5=D8F1E545D80C2045881C7F0525558D80,SHA256=0D9C3D6A6DF364F812D370258C1B3D3F97584E9F7D36569D06746EBA1695D368,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105231Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-memory-l1-1-2.dllMD5=9F77AA276A31F36805DF003F9E66BD99,SHA256=26425008D97A2EA8B95AF52BFE47CF5DE1DE9BB3E25DF77123B85C895192D7D6,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105230Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-memory-l1-1-1.dllMD5=728A5655624D5B091E8E216BE90D9EF9,SHA256=A2B17F63065CC760FA9CF5D2950D0E13613997546C90CFA1C094CF32171D49ED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105229Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-memory-l1-1-0.dllMD5=BA6B6729DC95AA60AF31A160E2CB4533,SHA256=AA433713D5D1DB4413E9F5D938C0C452BAE8EB1BF8CD011803464BBD893BBB08,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105228Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-localization-obsolete-l1-2-0.dllMD5=B5727AD79BEBAAB6E6AFA381A28A8E9C,SHA256=C0E101B6BCDDC28A9BA24C7796BBDAAEFC14459E402FD53053F3C23E0D84D040,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105227Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-localization-l1-2-1.dllMD5=FD9B6F1EA88B7167E6EC227A61B90888,SHA256=2FEF21096468EE5C6BFC88971AFDB4CC07F6C4669375561863B85023C15684AF,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105226Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-localization-l1-2-0.dllMD5=C8420A86D981BB6AA0D32001D234639E,SHA256=2E93EA8BB070C07C39B7F042B7D9843C4B74B3D4E69C8E33D89B0574B2D1D43D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105225Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-libraryloader-l1-1-1.dllMD5=787DCDC02E39A27A63B857FF6E819593,SHA256=91A7DEC7B636C00032D122CA04D4B8653B13E1211C54A4184F3955D2398C2E2E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105224Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-libraryloader-l1-1-0.dllMD5=AC90FCC4E819CD2EEED5D09A1FA42BAC,SHA256=2DA68FCBCE619BE5A90501F971467B7A894C6A705659346729E1E4E306EEB7D7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105223Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Core-Kernel32-Private-L1-1-1.dllMD5=E269D033D63A117DA8F3F855B90CCBFD,SHA256=41437C84BF757CC5758BF381600D0DECB00E8F8F56F11765203B7880AC4CDDD0,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105222Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.784{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Core-Kernel32-Private-L1-1-0.dllMD5=58B0B7C61F098BD1E73E9C156CB38C64,SHA256=C366B92E7048081C7B336CEAB970BAA20AFDAEE2456820AA38360D1429C27669,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105221Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-kernel32-legacy-l1-1-1.dllMD5=912D93DCBE67A1373D93BACD0174E3ED,SHA256=0B94CB7472E0777AEFC1B3208ADDE41B893B78B3223F515FB86348D3362624C3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105220Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-kernel32-legacy-l1-1-0.dllMD5=8E788763C9CDB6E5D1A313C08F7D621E,SHA256=5604FCC803BE14AD10C7A2372FB19BC80D43AD850109A670676982A4EC961473,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105219Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-io-l1-1-1.dllMD5=DC7E345A08B64DDD90906151E1D566E9,SHA256=ABDC082DAA40FCAF14E4E554DF23CFC48533F5A2157BD540BFEC49EB8E31E403,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105218Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-io-l1-1-0.dllMD5=A4381D04E233B96B657262DE9B31594C,SHA256=17BE2709D85E6B922BDF5D357FB4CD9416234F8E6685226F5EC776E8B3B5A678,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105217Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-interlocked-l1-1-0.dllMD5=39646EB20F4366691E3EFF958C99D1D4,SHA256=262D2C2EBAFFA4276F54B05A5A1DA125CC9DCCAF76EAAD3AAF7B23D54EC33C8E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105216Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dllMD5=0C5DE8F3B6CC9B44ED0A0556A02F4867,SHA256=D08261783A1749B08F7423923B00FD77E3B44265889B1F550A64239586BC8FC7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105215Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-heap-l1-1-0.dllMD5=51EBE577149EABD170684C2668F967ED,SHA256=0091D6C33047D8EF6E0F09E049DF2CABA5EE6B4F5B1870E0A369D3BF6DB72330,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105214Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-handle-l1-1-0.dllMD5=F83CB23123F3E4885547ED29F2BD2360,SHA256=495A9EC7C50D6D72F209E1F69C9B0C292D8D32FBE79FE675128786F8E351B988,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105213Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-file-l2-1-1.dllMD5=8B79E85DB9AA6D00794E5151455951BB,SHA256=EE600140599138132439FA9FB9FA6B028A9BF2A206A856CCB1106EFF45459C13,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105212Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\API-MS-Win-core-file-l2-1-0.dllMD5=455C1AB890C154076E0E23A42F10B6F5,SHA256=DB95D8AA71A8E0A54852C1A83E42267C72E26F2A111AD41146096BF26825FF62,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105211Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-file-l1-2-1.dllMD5=A9808572063E5A5649EA59F8B40FC7A8,SHA256=D4FD5081924D4B544188A687BD37127E0A38AF310E77C55F6EC22896B95B3C9C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105210Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-file-l1-2-0.dllMD5=4438E1D7952A77B7F71FF45EF821814F,SHA256=1C4FA5120E310E49C8112ACB6E594DB2F581AE4B6BA6241EEA4301E0E373959F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105209Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-file-l1-1-0.dllMD5=FF5C179E19923B65E650B11283250D50,SHA256=CF84455BC2AADF2960F0AE4D3691BF3032F412578CB2730A27848C6B26D00225,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105208Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-fibers-l1-1-1.dllMD5=A263189D905386A2A91CD2EB39D3365D,SHA256=7392027920D102DBE4C2C15590CC471063D6B1456CAA797BB71F8973C60B47FC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105207Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-fibers-l1-1-0.dllMD5=A1827E232474C845B7A495D1A4CA6169,SHA256=A95088251923F1233CA4F5675457D6D6B2A1601734D4B5451420298491864746,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105206Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-errorhandling-l1-1-1.dllMD5=E98BCC3FA25D6DB36D50786EF08DBADD,SHA256=7BDA00F42BE64BCC1022EC3000FE2582CDF4CC89083D868ACA9DCE982C98C52C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105205Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-errorhandling-l1-1-0.dllMD5=14E8A42D84E459F617344438903680EE,SHA256=1FCB6E1908C13B5184373E83B3C13FCF96B55E4FBBC8AAF4D6E9DA604DB75848,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105204Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-delayload-l1-1-0.dllMD5=762D2E52FAFE433C50648FC23D7C3E76,SHA256=53238588E10FFAABA96C751D34181BA04A869A0474757E79D9FE82ABC3DC7CFE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105203Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-debug-l1-1-1.dllMD5=1652E7B742F30832826B48E62485BFC7,SHA256=0362AFCDFB6CA89CDEE0DACEC94A5E45D6910B5337343149007DE2443050D154,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105202Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-debug-l1-1-0.dllMD5=E02F6786930435C736D71E9B6B898773,SHA256=4C0F43EAC3834878F16175B17427C0195A3213B7CDF9702447667D703AA29B54,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105201Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-datetime-l1-1-1.dllMD5=78876D83AA27E510EC3DC3355D034B92,SHA256=44A696C4626AF85EA565D651D7FAF5E21B6EB0C6EE47EE93419D8A7BAD565278,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105200Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.768{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-datetime-l1-1-0.dllMD5=CF9560A4450AC70C51866581802AE8CC,SHA256=A7A23DC37F028D38D2836CE881FCFF1FD066538588B207BBBCC3B1AB96E3AB62,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105199Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.753{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-console-l1-1-0.dllMD5=893E267BD0B91FADAC2A2BAE70FD0400,SHA256=17D17AC0383117E9A14D7687ECAA3B27AF1C71B89687A5C3E5B8761B2E64EDFC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105198Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.753{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-comm-l1-1-0.dllMD5=C7EC73197892D7F63059C10D19BD5D90,SHA256=768E17ED08111FD22BAAC8FAC00C7DD87F0E57FEFCDAC58CE04B868528B2FDFC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105197Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.753{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-core-com-l1-1-0.dllMD5=08A5A3129DCB52F3C4E51EE3C4A827E7,SHA256=3C6549832275052BCC2234CC4433D95407800ED65359F5147C4762EE0C71F712,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105196Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:16.753{AD5E2759-AA7A-6196-7EC7-09000000F101}1536WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\16B09432-C8C9-40D3-A0A5-882F3B2068CD\api-ms-win-base-util-l1-1-0.dllMD5=29CD6DDC6BADE9098B9A4402C6336D62,SHA256=B97C475AA8241C9B674E8C51C387AFAAA7977B036D9E2F7FAFB6CACC11D985BE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 10341000x800000000000000023105636Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.834{AD5E2759-AA7F-6196-83C7-09000000F101}20085096C:\Windows\system32\Dism.exe{AD5E2759-AA7F-6196-84C7-09000000F101}4848C:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\dismhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\Dism\DismCore.dll+273f6|C:\Windows\System32\Dism\DismCore.dll+8eaa|C:\Windows\System32\Dism\DismCore.dll+58d4|C:\Windows\system32\Dism.exe+cd60|C:\Windows\system32\Dism.exe+4bd3|C:\Windows\system32\Dism.exe+3c84|C:\Windows\system32\Dism.exe+26b9|C:\Windows\system32\Dism.exe+1db1|C:\Windows\system32\Dism.exe+21fed|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000023105635Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.836{AD5E2759-AA7F-6196-84C7-09000000F101}4848C:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismHost.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Host Servicing ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationDismHost.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\dismhost.exe {A74E7B31-E014-48E5-9EFA-64828E3782EE}C:\Users\Administrator\WIN-HOST-874\Administrator{AD5E2759-A1B1-6168-DD52-B32300000000}0x23b352dd2HighMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\System32\Dism.exeDism /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quiet 11241100x800000000000000023105634Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-winsvc-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105633Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-private-l1-1-1.dll2021-11-18 19:33:19.818 11241100x800000000000000023105632Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-private-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105631Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-management-l2-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105630Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-management-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105629Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-core-l1-1-1.dll2021-11-18 19:33:19.818 11241100x800000000000000023105628Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-core-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105627Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-security-sddl-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105626Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-security-provider-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105625Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-security-lsapolicy-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105624Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Security-Lsalookup-L2-1-1.dll2021-11-18 19:33:19.818 11241100x800000000000000023105623Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Security-Lsalookup-L2-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105622Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-security-cryptoapi-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105621Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-security-base-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105620Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-EventLog-Legacy-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105619Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-Provider-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105618Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-Legacy-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105617Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-Controller-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105616Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-eventing-consumer-l1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105615Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105614Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-devices-config-L1-1-1.dll2021-11-18 19:33:19.818 11241100x800000000000000023105613Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-devices-config-L1-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105612Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.818{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-xstate-l2-1-0.dll2021-11-18 19:33:19.818 11241100x800000000000000023105611Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-xstate-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105610Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-wow64-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105609Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-version-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105608Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-util-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105607Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-url-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105606Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-timezone-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105605Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-threadpool-private-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105604Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-threadpool-legacy-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105603Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-threadpool-l1-2-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105602Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-sysinfo-l1-2-1.dll2021-11-18 19:33:19.802 11241100x800000000000000023105601Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-sysinfo-l1-2-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105600Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-sysinfo-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105599Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-synch-l1-2-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105598Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-synch-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105597Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-stringloader-l1-1-1.dll2021-11-18 19:33:19.802 11241100x800000000000000023105596Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-stringansi-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105595Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-string-obsolete-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105594Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-string-l2-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105593Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-string-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105592Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-shutdown-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105591Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105590Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.802{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-shlwapi-legacy-l1-1-0.dll2021-11-18 19:33:19.802 11241100x800000000000000023105589Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-rtlsupport-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105588Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-registry-l2-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105587Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-registry-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105586Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-realtime-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105585Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-profile-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105584Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processtopology-obsolete-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105583Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processthreads-l1-1-2.dll2021-11-18 19:33:19.787 11241100x800000000000000023105582Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processthreads-l1-1-1.dll2021-11-18 19:33:19.787 11241100x800000000000000023105581Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processthreads-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105580Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processenvironment-l1-2-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105579Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processenvironment-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105578Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-privateprofile-l1-1-1.dll2021-11-18 19:33:19.787 11241100x800000000000000023105577Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-privateprofile-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105576Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-namedpipe-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105575Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-memory-l1-1-2.dll2021-11-18 19:33:19.787 11241100x800000000000000023105574Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-memory-l1-1-1.dll2021-11-18 19:33:19.787 11241100x800000000000000023105573Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-memory-l1-1-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105572Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-localization-obsolete-l1-2-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105571Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-localization-l1-2-1.dll2021-11-18 19:33:19.787 11241100x800000000000000023105570Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.787{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-localization-l1-2-0.dll2021-11-18 19:33:19.787 11241100x800000000000000023105569Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-libraryloader-l1-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105568Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-libraryloader-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105567Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105566Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105565Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-kernel32-legacy-l1-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105564Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-kernel32-legacy-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105563Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-io-l1-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105562Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-io-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105561Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-interlocked-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105560Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105559Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-heap-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105558Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-handle-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105557Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-file-l2-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105556Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-file-l2-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105555Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-file-l1-2-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105554Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-file-l1-2-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105553Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-file-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105552Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-fibers-l1-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105551Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-fibers-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105550Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-errorhandling-l1-1-1.dll2021-11-18 19:33:19.771 11241100x800000000000000023105549Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.771{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-errorhandling-l1-1-0.dll2021-11-18 19:33:19.771 11241100x800000000000000023105548Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-delayload-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105547Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-debug-l1-1-1.dll2021-11-18 19:33:19.755 11241100x800000000000000023105546Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-debug-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105545Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-datetime-l1-1-1.dll2021-11-18 19:33:19.755 11241100x800000000000000023105544Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-datetime-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105543Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-console-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105542Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-comm-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105541Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-com-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105540Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-base-util-l1-1-0.dll2021-11-18 19:33:19.755 11241100x800000000000000023105539Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\WimProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105538Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\VhdProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105537Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\UnattendProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105536Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\TransmogProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105535Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\SmiProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105534Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\ProvProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105533Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\OSProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105532Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\OfflineSetupProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105531Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.755{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\MsiProvider.dll2021-11-18 19:33:19.755 11241100x800000000000000023105530Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\LogProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105529Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\IntlProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105528Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\ImagingProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105527Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\IBSProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105526Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\GenericProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105525Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\FolderProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105524Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.740{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\FfuProvider.dll2021-11-18 19:33:19.740 11241100x800000000000000023105523Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DmiProvider.dll2021-11-18 19:33:19.724 11241100x800000000000000023105522Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismProv.dll2021-11-18 19:33:19.724 11241100x800000000000000023105521Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localEXE2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismHost.exe2021-11-18 19:33:19.724 11241100x800000000000000023105520Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismCorePS.dll2021-11-18 19:33:19.724 11241100x800000000000000023105519Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismCore.dll2021-11-18 19:33:19.724 11241100x800000000000000023105518Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\CompatProvider.dll2021-11-18 19:33:19.724 11241100x800000000000000023105517Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\CbsProvider.dll2021-11-18 19:33:19.724 11241100x800000000000000023105516Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.724{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\AssocProvider.dll2021-11-18 19:33:19.724 11241100x800000000000000023105515Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.localDLL2021-11-18 19:33:19.709{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\AppxProvider.dll2021-11-18 19:33:19.709 10341000x800000000000000023105514Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.709{AD5E2759-5433-6143-0C00-00000000F101}7321852C:\Windows\system32\svchost.exe{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5126|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000023105513Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.693{AD5E2759-AA7E-6196-82C7-09000000F101}32084632C:\Windows\system32\conhost.exe{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000023105508Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.693{AD5E2759-A1AF-6168-1D61-04000000F101}2172520C:\Windows\system32\csrss.exe{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000023105507Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.693{AD5E2759-AA7E-6196-81C7-09000000F101}46606132C:\Windows\system32\cmd.exe{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\system32\Dism.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+1ace3|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000023105506Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:19.701{AD5E2759-AA7F-6196-83C7-09000000F101}2008C:\Windows\System32\Dism.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Image Servicing UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationDISM.EXEDism /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart /quietC:\Users\Administrator\WIN-HOST-874\Administrator{AD5E2759-A1B1-6168-DD52-B32300000000}0x23b352dd2HighMD5=DD0DC0C490755CEA51413D940B31CF0C,SHA256=71C182B3550A7DCC61B56C2D7E363673574CD03000A5081C0A228D775ECAC133,IMPHASH=07D06C9BFC08891808D6DE5FCD00BC8A{AD5E2759-AA7E-6196-81C7-09000000F101}4660C:\Windows\System32\cmd.exe"C:\Windows\system32\cmd.exe" 23542300x800000000000000023105804Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.459{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\WimProvider.dllMD5=1B0C7DFB2240BA004B37904073624DB3,SHA256=F2C7DB522DDE968EDF49B03BC10978AAC4C42C745CA4A474627E8CEBBCEBB00A,IMPHASH=20D31D66F56B810094B1AA564C92009Dtruefalse - insufficient disk space 23542300x800000000000000023105803Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.459{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\VhdProvider.dllMD5=F37C8F5BF852151D9BF085687A8DEC6D,SHA256=6CDFC95C2F2ED3695D5EE8CF4367A6C7FB5707DA3C234CEE8FA8C1BBDE426DE7,IMPHASH=3CA997A1A0BD38B850B18DAED5E948DEtruefalse - insufficient disk space 23542300x800000000000000023105802Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.459{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\UnattendProvider.dllMD5=3DB4777B76FC1973A61754FAEC348981,SHA256=29A4C7379E5A0A7532C90B5ACE0DD99AB5311D03CC0BA6A4BCFB410D7D8B01AE,IMPHASH=4FA75E8720452554D61C8AC5FD64C43Ftruefalse - insufficient disk space 23542300x800000000000000023105801Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.443{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\TransmogProvider.dllMD5=5E82E2B7CFF045C7CDA8E33EAB186402,SHA256=0038B82E999C3DEF3980D39A8CAED9EA6B52A4FC9EF58BF3B3F5FC91F7748112,IMPHASH=7746C0E3C7D3763C5F13C90D4934087Btruefalse - insufficient disk space 23542300x800000000000000023105800Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.443{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\SmiProvider.dllMD5=C5C7A9E3121B91E51ECFBA6FB2985044,SHA256=FB519B9EEF4C3344D58C768BD3AD7ADCB0677EA7B998056B6A13620CB9E61412,IMPHASH=03C38376DA7CCE75E82EECACADA0EA03truefalse - insufficient disk space 23542300x800000000000000023105799Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.443{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\ProvProvider.dllMD5=5077063311C5708318C5FA3E255011ED,SHA256=97FA95102B6ACF00C70F140EE9FA4A73A6BE7C03E0F0D99AE58DB5E492CD0ECA,IMPHASH=D8DD764BFC0F1D9E403714D169018B83truefalse - insufficient disk space 23542300x800000000000000023105798Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.428{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\OSProvider.dllMD5=4868187A2F176074DB7F35E356F74D4F,SHA256=84C8C4C67C808871A278254304D985533F67D44391840F43674FC829014E1B60,IMPHASH=82A4D833A82D441391A9AA3027199337truefalse - insufficient disk space 23542300x800000000000000023105797Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.428{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\OfflineSetupProvider.dllMD5=86B7E8438B1125C479FD275B1BDDB9A7,SHA256=47FAF8671B25A30D7BCC47AD35926D70DB633A181FA6C276479B4408A526E63E,IMPHASH=B8B4A188EFC4F12D33591C6D319B6F12truefalse - insufficient disk space 23542300x800000000000000023105796Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.428{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\MsiProvider.dllMD5=EA19239A85416A488360FA564D312402,SHA256=F21591336CD1A24EE941827620405FA34414C1C349216B4B8083ECD1FFF17C29,IMPHASH=33E1132923056DDEFB0521726DA5B987truefalse - insufficient disk space 23542300x800000000000000023105795Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.428{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\LogProvider.dllMD5=F7DB4F104DBB56DF5A156E7329E80112,SHA256=7C67EFAF44D1413576B4575B1A4C975BCB10B64BEF13E6756E895D4DB9E61AA2,IMPHASH=FB695172E8A76C56E97CE435F8ED0220truefalse - insufficient disk space 23542300x800000000000000023105794Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.428{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\IntlProvider.dllMD5=0082903881275179642AE83EFA720310,SHA256=7CCF1625E6FBE4DB16F12AC037E4236A3EF269DEE47A157C68374C867941F9E8,IMPHASH=CFB81BC5FF922F23D605A653700FE666truefalse - insufficient disk space 23542300x800000000000000023105793Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.428{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\ImagingProvider.dllMD5=EEB4AA36BAD26A2C6216A1FF3439B58C,SHA256=44A6679425039DC870C297294C4B3323F6FA9DE5C7D16D7D0AB7E1254AFC75D3,IMPHASH=0264D9B4BFE54732ADF0E29BC73BF280truefalse - insufficient disk space 23542300x800000000000000023105792Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\IBSProvider.dllMD5=11DE34FCDB75E79A920D3B491F3E7BF0,SHA256=6B7C7AD8B1AD522B27B2CC5E4F76F56ADE4495D7D46CE4F997A68954F072AF17,IMPHASH=C755896FA14213058E34639A28868FBCtruefalse - insufficient disk space 23542300x800000000000000023105791Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\GenericProvider.dllMD5=397ED660129D40927A27B75A4B8FAE2E,SHA256=EAFCECFE911DABB4531E1331DDF2E119DCBB6B7A887D70BDE737EA76BE10EB74,IMPHASH=F55EE75573C110804DE5E50ACEEC1B06truefalse - insufficient disk space 23542300x800000000000000023105790Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\FolderProvider.dllMD5=6428B4D0C26DB23E9478F039891CD5C9,SHA256=55126BB099785C2F9CD32A30991082C47D62C8231D570A9D8A6F3CC599B25EE1,IMPHASH=B2CC5EDD42A866F7CB6CAE42DB969187truefalse - insufficient disk space 23542300x800000000000000023105789Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\FfuProvider.dllMD5=E27BC7F808E72F08372BA3C40B4B6344,SHA256=927B194432046C0D2ADF7C7B71E4BE85602C4D00A5D6EDA9F9DB9924E1C3447A,IMPHASH=8580AF5C1871319D05329DB2E96A8146truefalse - insufficient disk space 23542300x800000000000000023105788Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\WimProvider.dll.muiMD5=CC3B15540DDB521A300BAFF0BF4F902E,SHA256=33C06CC037DF1EBB72A15BCC2E09BC89DFEF7DD94441C650FD3D0C833122002A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105787Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\VhdProvider.dll.muiMD5=10536C56F02E68EBD13D0B2CE8665C6A,SHA256=06C3B71D251A8DD47D02EDBFBE84E0B6B1D67956DE4D3996031434CBAD728929,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105786Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\UnattendProvider.dll.muiMD5=B7E3676672BE6851EA13ADD879C2945E,SHA256=2D2D82EE842CD346B58DCAFAE6FEC46D491E0D15CFBE0D8964A4AB7F18C5AAB9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105785Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\TransmogProvider.dll.muiMD5=D5D596B1102DA565C2ED1FAAC170E758,SHA256=B5DBB36E947FD64AAF22C53F0A9634C7D72D4CC270C055B67E020920BF806909,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105784Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\SmiProvider.dll.muiMD5=CAD746ED5AF63E7FC49ED4A5A3984629,SHA256=016C6071B04E6D7E12AD9B8A85C002320331E01ED62922C573A1AC43BA0DD919,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105783Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\ProvProvider.dll.muiMD5=70AFEC86B6CF677BF8D3C713CA3281FB,SHA256=C8579EC95A51EB663FFC6145F0998C2F1930A6B8146C84C0A9094BCA4E5195A7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105782Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\OSProvider.dll.muiMD5=A464DFEDEA8520616AA9B2ACD166A77F,SHA256=54E985CFF256CEBE82E9EF3E814A5FDA9FF730BCB50265E9BA78DE65A4DE3F42,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105781Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\OfflineSetupProvider.dll.muiMD5=CED788DBD9D13D0490B2F642B0B051F6,SHA256=D5DBC0A52B598800EE14569859383525950B865F4816E47E2E73F79AA1C32A09,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105780Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\MsiProvider.dll.muiMD5=5AE9ABD6BB469F3AD7B3A4CCD40974BF,SHA256=C2CE66F2F218890AA76F8BAB68B4C0FDCED0688E694F912F3A5BFABFA6CDB5E7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105779Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\LogProvider.dll.muiMD5=0D4519BC8EB58A006E4A5EB993C0DCCF,SHA256=DAFFE67521F9B4657FBFEF9585234CB39293F9B866C0D97D66F675037515BB51,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105778Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\IntlProvider.dll.muiMD5=16ACB74928BC55FD4AAC316F3B92E1D7,SHA256=17CB486CADB679C75A27BA6C76E2FE714F4B8DA845E6F795759517D6734F0BC9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105777Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.412{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\ImagingProvider.dll.muiMD5=26F5BBF8D6EE90B4F47C18E93D1087FB,SHA256=F41738FEF7140176447ECF371B1117A485E48BA6F3E9AFAA8C4F883ABFAE62DA,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105776Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\IBSProvider.dll.muiMD5=0B09FE334215A8E736B2CF08A50D5204,SHA256=DCE9AD3B79F91BEBEDDFCD9E03F1557CB7C6114AC906081E9E046F807093CDF1,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105775Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\GenericProvider.dll.muiMD5=956B8B45B92321C0D5975EE9A6C5B773,SHA256=578541D71466CF61EF399023B34EDFCBD915142BE856534AD4D17D25E7CC9F3D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105774Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\FolderProvider.dll.muiMD5=DC4E4C2800DC6D98F7893044A21D246B,SHA256=8B4CE62F4E4294E701193C7AE393EB5EB29AA45932D376CB1A03728A140096AE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105773Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\FfuProvider.dll.muiMD5=5ECAD70AC2B3A95CBB42D6FE67D2F726,SHA256=C210389DBB9B7B4A802E4B0C3C708B6F55B086564A01E19CFB183B6AF916C30A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105772Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\DmiProvider.dll.muiMD5=38C2A1560C340537C3AE0CE04BDF7EAA,SHA256=52B06DFD85FB5AB1DCE2BE665CA144B1AE6658F518D1623D9B44C347C482B064,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105771Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\DismProv.dll.muiMD5=BD7B77B3EE9A12FF3F5446ECDF80B5C6,SHA256=B972A0B2C4682E9074441B481BD886DE19B8DB3DBA401B88E980B154C14D5A7E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105770Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\DismCore.dll.muiMD5=C901FF639EDFBBE710D6E5882F07CD24,SHA256=9BDA61D23DC50F9AFA82DA94B06B7B9C8229D5ED666D2F5270DAE13100815C27,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105769Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\CompatProvider.dll.muiMD5=A2A344CB32B6835744A36D877C952665,SHA256=A74D765B796638A921C4810D1712A08F7A37C9BA9E91F4DFDCB9727611C3D18D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105768Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\CbsProvider.dll.muiMD5=179B34BE97A383AF3E757031E7DA964B,SHA256=ABD3824664D1336EE849D89BA178606CC1B1E23E173752D8093F34A5580FA8F4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105767Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\AssocProvider.dll.muiMD5=386FE7AC95738A0CB6D25DEA662991F1,SHA256=22DC7317108A528BA92C853330598F628B93FFF27CAC34C2F501B806A75261D9,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105765Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\en-US\AppxProvider.dll.muiMD5=9FF5081115C2C21D9F85AF7EE6D2CC63,SHA256=107B10A8C1426F1C0D703F06832D740A4CFDCAA596FA0EA147A32A736A7A2A4D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105757Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.396{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DmiProvider.dllMD5=FC76385FF00D4A93618D842B41716D8D,SHA256=BBD49A49CFFA8411FFA91B02541F5F3B5333FD9055BC129DDD3B36EB005C34D9,IMPHASH=062B279D8ED4374A0CD0C84620F4BE4Etruefalse - insufficient disk space 23542300x800000000000000023105756Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.380{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismProv.dllMD5=8C7D97E22045AE402EA896F514CEED81,SHA256=76D3202E11BA22D277532A14CAE60E596975C0D8C34C7BE154F453EB1F7C37EF,IMPHASH=0247CB1C8FD55E43A448E359883057DBtruefalse - insufficient disk space 23542300x800000000000000023105755Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.380{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismHost.exeMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424truefalse - insufficient disk space 23542300x800000000000000023105754Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.380{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismCorePS.dllMD5=FB88731B484D1FF4AFF5DB75A20799FA,SHA256=EA155388211E0C3CEF2C99BD5F341C9F93F1ECDA6F21096DB6F9DB2110686A52,IMPHASH=65E10DCEA11F7117C161DC7557B87689truefalse - insufficient disk space 23542300x800000000000000023105753Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.380{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\DismCore.dllMD5=F1AB58CACD95921A04225222D03CDEA0,SHA256=EDE89F377FD46F95639413411CDA072D9FF63E72A399B26AB4870094F145091B,IMPHASH=B7B56C790C8AB7134B0680D8DFE46658truefalse - insufficient disk space 23542300x800000000000000023105752Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.380{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\CompatProvider.dllMD5=E5C1D020198EBEC1D5ABA640C9A600D0,SHA256=A80FD2846E05AB491BDAAFCE8854A04549A852066B82B90D757D9B6A44ADA8C8,IMPHASH=2CDD615C09EED7B572606B2A0C0EFD2Ftruefalse - insufficient disk space 23542300x800000000000000023105751Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.365{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\CbsProvider.dllMD5=D4A64C7C50D0C6BE9F8770177E2264BF,SHA256=E6505F9DBE17DF9E7E52B5FE1720E1F6482B25D262A47A320CF438C5FD5A5797,IMPHASH=99D5DC4FF67AB12670853DD4E32E8358truefalse - insufficient disk space 23542300x800000000000000023105750Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.365{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\AssocProvider.dllMD5=56CB83B3454882509791FBA62832BC87,SHA256=5B01524CC03B6EB58CC9E0FF479014EAF89EE7FDE2791BFF871BC90274D200AC,IMPHASH=83F73507B4613B09C6FA825535D8A81Etruefalse - insufficient disk space 23542300x800000000000000023105749Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.365{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\AppxProvider.dllMD5=8F6792DF9EC54934B76A68B1D7B66ECA,SHA256=E57CB2D5CEC5E1354F4E31CD08ADA02FCAA0E2DEA4B28C8F61683BFA3E875C05,IMPHASH=F1558CACACA712554EBD5926B4B3FE52truefalse - insufficient disk space 23542300x800000000000000023105748Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-winsvc-l1-1-0.dllMD5=09934F0F7227B9489D117C26EC20CD14,SHA256=CBE408A0AFF90986A6A7DDF022F96302B4FADD08A0C3C166CAC7A64D6ABF041D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105747Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-private-l1-1-1.dllMD5=484ED248F1A72C6E4E6F6C3F5A3339ED,SHA256=00E14515FE6FEBBF3C2CFC89A6F1A3D6F48B3E7A5EB08D50DADF69CE3F34CC47,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105746Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-private-l1-1-0.dllMD5=FEBE55EA884F3C1EE45ADE2734AA6BE6,SHA256=CD51DF334A600117133C9C8100DDE766D980456988FD333A40BE5A81C8092340,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105745Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-management-l2-1-0.dllMD5=0D45D811001E0A7683A2B7CA8A883874,SHA256=F44E2A85D7507159AE115C85C3497C57BE4ECB2D6ADDB30A534110266D56F92F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105744Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-management-l1-1-0.dllMD5=C36912B3A28B06F5BB24FE9BE49DA4D3,SHA256=D737A832C0D595E8E52846C2D748B911D7155E372F43FBB10513CFDE0BBF83B7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105743Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-core-l1-1-1.dllMD5=A86D518BCF3970C17A1768792FDF37FF,SHA256=AB5CC1B14D6BB708B5C87C2622DA886E2119A6997E08108CCE36080385DAEE71,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105742Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-service-core-l1-1-0.dllMD5=A329C75641638E2FFA11087F614FD4C1,SHA256=5071AA303D436407D195EF37889F018BE7E350DA5E690793587458D4C6D308DB,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105741Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-security-sddl-l1-1-0.dllMD5=C6C6C3E4D7CFA93246362901750A94D9,SHA256=6E274ABE823EF8B30629A99D9F942794C9FE6D003021A0C5085B49A7D8611DDE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105740Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-security-provider-L1-1-0.dllMD5=207B5716605CA4850629F3E2FFFA07BB,SHA256=BE6E6284F69C76BE6366EA8D44D85BDBAB6A71DD42E8B5575CFDF671AD58DCA2,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105739Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-security-lsapolicy-l1-1-0.dllMD5=FE7AD7265E296947172B8C491E8109D2,SHA256=4D231AC65F0F54BFF45CACFFE7DF3109CF87F78D14960EC8F03654E605AC8ABF,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105738Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Security-Lsalookup-L2-1-1.dllMD5=EBD6475839F5C99FB8855A80E0FC2AF1,SHA256=F519C7AA6930DAC83A3045CEEE42F64F26FFC54254D5ABD1B0F7D99C47569A30,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105737Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Security-Lsalookup-L2-1-0.dllMD5=AC284A6251F5D26633AF48D918D09628,SHA256=F7A34B793AACF75DA4EAE843B6088C0BAAA8B835EA5F6A65E72EBD9A1479C8A8,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105736Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-security-cryptoapi-l1-1-0.dllMD5=DE0A49D4B2E9A5FA6762BD191C622B32,SHA256=AB12FEAF15CB313812B01AFE1198B62E72F7702D140830ABAD2CFB6251E82A7C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105735Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-security-base-l1-1-0.dllMD5=DC4B661366FEAA4ED54FB1004D9E7A3D,SHA256=B4018F8F249CE087DB46F61A0C2E947248A5B71576F511F0B3650433607BC663,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105734Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-EventLog-Legacy-L1-1-0.dllMD5=B8B7B02C3C66638EC0BDF49BCF04A680,SHA256=5D1103E89199731DFFF7BF89D7F6484C038D47CC04F730CD5233EDE488272E6A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105733Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-Provider-L1-1-0.dllMD5=FEAA05CE6CCB92AA7B2A2C58C049891A,SHA256=31A4AE262E179DF4CA406E1AF90F651935657BB5FD990C675C67E37D5B834CFE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105732Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-Legacy-L1-1-0.dllMD5=88450242D5350529CC8E46FD9C3F3B7B,SHA256=312B6BFC89B551F2C4E8FEDAB316DBE01F190CD5E67091AAFB0E6F67616DC745,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105731Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.350{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-Controller-L1-1-0.dllMD5=00A27A81EAAE90C9CED7063013877357,SHA256=DC4EE086FC046E1D7A291EA3B8B13E77B7A252B5C283B8F6C9CEC729070B7822,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105730Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-eventing-consumer-l1-1-0.dllMD5=61958A4BE8F944BAFB29DF8009541FCD,SHA256=3B7CB5622BEAC7D633A84EE2F7336C8DE1D3D1AA10577D98020081AB67761FAD,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105729Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dllMD5=8500E093D6B36DF1AF271F6EB34227CA,SHA256=99E2CD36104D3EFD4DEC88AD0F4BED1FD1BBFA97CC4FB29DB7F7136290DD6B70,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105728Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-devices-config-L1-1-1.dllMD5=5A03B636125C21AB918D2CB04843DBA8,SHA256=C914CD6FE6C7B16533763BC789EDAF67D7A19C26514C927572051C4379C79FC0,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105727Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-devices-config-L1-1-0.dllMD5=0C61A8D9CF9BBF6D771BEF0FF4A43E23,SHA256=66807B95E13944D52E9A7AA1F1A41E632FAA46F6B48F98451618DB3845622577,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105726Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-xstate-l2-1-0.dllMD5=56A386E38B637FCD96CED04CEFBCF8DE,SHA256=A5BE1E3C71A3A5C8EEF4BFAD9D0BADC97BA47B2B9911CED4BD1B8F65BB8DCB77,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105725Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-xstate-l1-1-0.dllMD5=6A982D13DDB295E59F90FF23EDD2E60F,SHA256=3617DBCADFE370463B4DBB91C1C6222923F16EC362DE29C2CA3AE4E72C9ABB64,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105724Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-wow64-l1-1-0.dllMD5=AE7573E1DC370B9A8FEBCC17A6C82FF8,SHA256=59A473D1AD7C181C89AF00B966CD107F1846CDC526009C4807A1EAE3DCB3731D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105723Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-version-l1-1-0.dllMD5=5CB34501C2D784D31281FD526B0BB963,SHA256=E45B73AF0C35F05B01CADF6BD4F67C1497586F4C4F9A16F0448BA751E16C4596,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105722Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-util-l1-1-0.dllMD5=212DA9E9AD6BB61A3554A4174BA558CF,SHA256=01291D3895EC5BB0E658F91FE1512AADCBB6D8F1154BC6023076554AFA05AC1D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105721Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-url-l1-1-0.dllMD5=198A08F8150D7575CC207CFFCF67D66C,SHA256=86F6DA0F1D075B7E1678DF71689948FEC334CFB10316FEB40E5107135548F9B4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105720Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-timezone-l1-1-0.dllMD5=4D7C132D9742FFA44248B1BBF32020FB,SHA256=58A65C1938DCDF64D2930B037E9D133A5ACDF46365835782869D3216D3CF2CED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105719Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-threadpool-private-l1-1-0.dllMD5=A9BC53B62CD4B269B8385ADBE0AE808D,SHA256=A30003AB0C020E433CC5296E7E150BB11820395D439062FF7FD6D7F449C4C5B3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105718Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-threadpool-legacy-l1-1-0.dllMD5=CAC86F4298EB2D239410B3338780DC34,SHA256=1D99842180A612D63F1A8B137A9BF0375B7113AAB325916BA4781AB8A7B68E7D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105717Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-threadpool-l1-2-0.dllMD5=D32DDF80AB3F1F96F431E5672DC1F387,SHA256=E2F0F0D46082ED40D042BCCD47F4E917707CF884672C5919116126914FAD4572,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105716Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-sysinfo-l1-2-1.dllMD5=E83097DFE144367FA2231828F9FD89A6,SHA256=69FA978126192DBAB6AF11C9878D9C2BD1FD7E3FC899300244DFA4A1AC7ACA31,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105715Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.334{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-sysinfo-l1-2-0.dllMD5=8D842EBFFA7803451A3AC7D6907A6AD9,SHA256=808C22A733B5F6A4E601605DCF4043C9952CEBE825FF2622097FC5B4FACF682A,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105714Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-sysinfo-l1-1-0.dllMD5=376E34D4A8F94C94FFF063810717612D,SHA256=5285A11016967E2017A8187882579CBD722371D0B7497B356149FC447160A521,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105713Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-synch-l1-2-0.dllMD5=E19F4FA6A6313F00ADE8AF26649A0BA1,SHA256=386F6CC0C3CE0C904A44A2FDDD11B2E5EA7782B08E69FD961DA5BE3C32BA5C26,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105712Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-synch-l1-1-0.dllMD5=95088E453B41A8B50E7340E6DE9CD09C,SHA256=E4938C16CA5FC7A8C9D87E4201FA2F28992026F5858F36A2A44EA22B5BD0889F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105711Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-stringloader-l1-1-1.dllMD5=FE1D00B19175DE6E9729F709C508DD6B,SHA256=D726F32AEB323F4DEA55D35441D1FF06BF3E212846A6B86D9ADC8F9DD1307B57,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105710Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-stringansi-l1-1-0.dllMD5=43F8D61E2EE0E253B973EFED0B3EBC8D,SHA256=1B9FA225A474D42FF8360141C8BC1EE1E7310958910931AC8E5A213E957700BD,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105709Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-string-obsolete-l1-1-0.dllMD5=92C0A4E592B5D773C562A36CBA4E6E47,SHA256=5191E82E921398310FE9FD333F5CA44E6233358499EDD5B33BF8E9F0C9D3B88E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105708Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-string-l2-1-0.dllMD5=3E1902AF98905F00E62B1EC827EB0FC2,SHA256=503443DBF6E6E481EA1C661109CE17B3D55C4FEA001D77F11CD032BDDF64FD29,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105707Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-string-l1-1-0.dllMD5=D30D4587D051D288D1023DB0D826295A,SHA256=DFE66C8C205C95274565BADB7B3C19043917F6CD07A8DE34CE241EFFF9EA6676,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105706Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-shutdown-l1-1-0.dllMD5=1D8D1283F8279BDDACF8745AEDA3DB2A,SHA256=21BF3432160DD9851CAAC716DF3A41E39428A84BA9B9D3C63CDD300CB6928300,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105705Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-shlwapi-obsolete-l1-1-0.dllMD5=33BEFB60C3DC3E93FCE54A0515100181,SHA256=24B3FA4C5E8AB463BD2CFB704D7BFA7E8429726852EF582F94E44D7691BDD1FB,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105704Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-shlwapi-legacy-l1-1-0.dllMD5=699CDC66AA090D13EFF451F2006944CF,SHA256=6212B2B8CF5533F9DB6E366BBADED7A8D6EAD6667EA6A425B6987102669D8D96,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105703Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-rtlsupport-l1-1-0.dllMD5=F9672F68330CD16B0D1FA3A75B123AE8,SHA256=C5938839A3DFFBFBFEF432D0A95D0773375B4758FC160EDD04383A4B4273A18B,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105702Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-registry-l2-1-0.dllMD5=BBC015F33C0C3C2F9FC58C466BF8A30A,SHA256=1ED3511DC98353CA8E9B22A40C318BBD24484C25C171886B06B22AFD396ACFE8,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105701Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-registry-l1-1-0.dllMD5=D132FADCBF190A1C68070E6D488E67D7,SHA256=E6F51C07641EF931C4F97E5D966242BB96A156A603A7769BEAE0EA61E9E25486,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105700Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-realtime-l1-1-0.dllMD5=792C54B79CA333ABBB51BE66815A98CF,SHA256=1E3B3505560AB3E641C386473A83AA194D94CD5BC6CC4FA718D003D1FF899601,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105699Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-profile-l1-1-0.dllMD5=C4E53285E8C51DCBEFF5098215759D69,SHA256=320A6138FE915BE7E83F4CDC2024531948185C3BFC939CB367A53F1AA74BFB2C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105698Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processtopology-obsolete-l1-1-0.dllMD5=99E3ACC47F10000AE67A577F5893FD5A,SHA256=AD01524D3FDDC25C91292808E7B333B587C902E996E557885E79CC10F9A66214,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105697Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processthreads-l1-1-2.dllMD5=DABFBC1EAB7AEE555F3BAEAF981EC7EB,SHA256=3070505B0B060D9EE9C2B699A518481A22DC15ECAF9603089FCF9EBC022179C3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105696Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.318{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processthreads-l1-1-1.dllMD5=8C5DF20B2E2DE6BA6717A597A951E4F7,SHA256=BE42C78E3F21CD6E74811F27E1B76C4FE8537FB149EF34EA455F22AAA29720ED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105695Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processthreads-l1-1-0.dllMD5=3D0CD1FE610E55E8C151162004A1429F,SHA256=D43535460D9CF2F2D348E9F2027DAF9FC0C0C906D5066E15F86332C839C94651,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105694Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processenvironment-l1-2-0.dllMD5=BB20192D0B22AD2EBBF4960B66D2E164,SHA256=23E758C4F7646AACC2DE8B8930BB272115F726F27E5437DF606E1C2328FA48F4,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105693Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-processenvironment-l1-1-0.dllMD5=2CF62C9CF255C15AD1C8B1CCDD9453D6,SHA256=35CDE2048D4EC8D5D02B1CA57B81B8D5F579541EDBAF5DA4485A6323B8C3A805,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105692Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-privateprofile-l1-1-1.dllMD5=FA8EFF9B35BE58F70CD0014DAF108819,SHA256=835F086B0884E8E1689D661657F258FA1E71439672E9F0CC0140D614DAB6FA6F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105691Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-privateprofile-l1-1-0.dllMD5=C8490BC5ACB353CAF140CB12670883A2,SHA256=85F3FE5E802843596F466D479111658B08271E48CC1821EB17E6D299D523C95E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105690Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-namedpipe-l1-1-0.dllMD5=D8F1E545D80C2045881C7F0525558D80,SHA256=0D9C3D6A6DF364F812D370258C1B3D3F97584E9F7D36569D06746EBA1695D368,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105689Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-memory-l1-1-2.dllMD5=9F77AA276A31F36805DF003F9E66BD99,SHA256=26425008D97A2EA8B95AF52BFE47CF5DE1DE9BB3E25DF77123B85C895192D7D6,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105688Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-memory-l1-1-1.dllMD5=728A5655624D5B091E8E216BE90D9EF9,SHA256=A2B17F63065CC760FA9CF5D2950D0E13613997546C90CFA1C094CF32171D49ED,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105687Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-memory-l1-1-0.dllMD5=BA6B6729DC95AA60AF31A160E2CB4533,SHA256=AA433713D5D1DB4413E9F5D938C0C452BAE8EB1BF8CD011803464BBD893BBB08,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105686Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-localization-obsolete-l1-2-0.dllMD5=B5727AD79BEBAAB6E6AFA381A28A8E9C,SHA256=C0E101B6BCDDC28A9BA24C7796BBDAAEFC14459E402FD53053F3C23E0D84D040,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105685Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-localization-l1-2-1.dllMD5=FD9B6F1EA88B7167E6EC227A61B90888,SHA256=2FEF21096468EE5C6BFC88971AFDB4CC07F6C4669375561863B85023C15684AF,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105684Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-localization-l1-2-0.dllMD5=C8420A86D981BB6AA0D32001D234639E,SHA256=2E93EA8BB070C07C39B7F042B7D9843C4B74B3D4E69C8E33D89B0574B2D1D43D,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105683Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-libraryloader-l1-1-1.dllMD5=787DCDC02E39A27A63B857FF6E819593,SHA256=91A7DEC7B636C00032D122CA04D4B8653B13E1211C54A4184F3955D2398C2E2E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105682Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-libraryloader-l1-1-0.dllMD5=AC90FCC4E819CD2EEED5D09A1FA42BAC,SHA256=2DA68FCBCE619BE5A90501F971467B7A894C6A705659346729E1E4E306EEB7D7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105681Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Core-Kernel32-Private-L1-1-1.dllMD5=E269D033D63A117DA8F3F855B90CCBFD,SHA256=41437C84BF757CC5758BF381600D0DECB00E8F8F56F11765203B7880AC4CDDD0,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105680Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Core-Kernel32-Private-L1-1-0.dllMD5=58B0B7C61F098BD1E73E9C156CB38C64,SHA256=C366B92E7048081C7B336CEAB970BAA20AFDAEE2456820AA38360D1429C27669,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105679Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-kernel32-legacy-l1-1-1.dllMD5=912D93DCBE67A1373D93BACD0174E3ED,SHA256=0B94CB7472E0777AEFC1B3208ADDE41B893B78B3223F515FB86348D3362624C3,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105678Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-kernel32-legacy-l1-1-0.dllMD5=8E788763C9CDB6E5D1A313C08F7D621E,SHA256=5604FCC803BE14AD10C7A2372FB19BC80D43AD850109A670676982A4EC961473,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105677Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-io-l1-1-1.dllMD5=DC7E345A08B64DDD90906151E1D566E9,SHA256=ABDC082DAA40FCAF14E4E554DF23CFC48533F5A2157BD540BFEC49EB8E31E403,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105676Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-io-l1-1-0.dllMD5=A4381D04E233B96B657262DE9B31594C,SHA256=17BE2709D85E6B922BDF5D357FB4CD9416234F8E6685226F5EC776E8B3B5A678,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105675Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.302{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-interlocked-l1-1-0.dllMD5=39646EB20F4366691E3EFF958C99D1D4,SHA256=262D2C2EBAFFA4276F54B05A5A1DA125CC9DCCAF76EAAD3AAF7B23D54EC33C8E,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105674Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dllMD5=0C5DE8F3B6CC9B44ED0A0556A02F4867,SHA256=D08261783A1749B08F7423923B00FD77E3B44265889B1F550A64239586BC8FC7,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105673Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-heap-l1-1-0.dllMD5=51EBE577149EABD170684C2668F967ED,SHA256=0091D6C33047D8EF6E0F09E049DF2CABA5EE6B4F5B1870E0A369D3BF6DB72330,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105672Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-handle-l1-1-0.dllMD5=F83CB23123F3E4885547ED29F2BD2360,SHA256=495A9EC7C50D6D72F209E1F69C9B0C292D8D32FBE79FE675128786F8E351B988,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105671Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-file-l2-1-1.dllMD5=8B79E85DB9AA6D00794E5151455951BB,SHA256=EE600140599138132439FA9FB9FA6B028A9BF2A206A856CCB1106EFF45459C13,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105670Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\API-MS-Win-core-file-l2-1-0.dllMD5=455C1AB890C154076E0E23A42F10B6F5,SHA256=DB95D8AA71A8E0A54852C1A83E42267C72E26F2A111AD41146096BF26825FF62,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105669Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-file-l1-2-1.dllMD5=A9808572063E5A5649EA59F8B40FC7A8,SHA256=D4FD5081924D4B544188A687BD37127E0A38AF310E77C55F6EC22896B95B3C9C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105668Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-file-l1-2-0.dllMD5=4438E1D7952A77B7F71FF45EF821814F,SHA256=1C4FA5120E310E49C8112ACB6E594DB2F581AE4B6BA6241EEA4301E0E373959F,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105667Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-file-l1-1-0.dllMD5=FF5C179E19923B65E650B11283250D50,SHA256=CF84455BC2AADF2960F0AE4D3691BF3032F412578CB2730A27848C6B26D00225,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105666Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-fibers-l1-1-1.dllMD5=A263189D905386A2A91CD2EB39D3365D,SHA256=7392027920D102DBE4C2C15590CC471063D6B1456CAA797BB71F8973C60B47FC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105665Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-fibers-l1-1-0.dllMD5=A1827E232474C845B7A495D1A4CA6169,SHA256=A95088251923F1233CA4F5675457D6D6B2A1601734D4B5451420298491864746,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105664Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-errorhandling-l1-1-1.dllMD5=E98BCC3FA25D6DB36D50786EF08DBADD,SHA256=7BDA00F42BE64BCC1022EC3000FE2582CDF4CC89083D868ACA9DCE982C98C52C,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105663Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-errorhandling-l1-1-0.dllMD5=14E8A42D84E459F617344438903680EE,SHA256=1FCB6E1908C13B5184373E83B3C13FCF96B55E4FBBC8AAF4D6E9DA604DB75848,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105662Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-delayload-l1-1-0.dllMD5=762D2E52FAFE433C50648FC23D7C3E76,SHA256=53238588E10FFAABA96C751D34181BA04A869A0474757E79D9FE82ABC3DC7CFE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105661Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-debug-l1-1-1.dllMD5=1652E7B742F30832826B48E62485BFC7,SHA256=0362AFCDFB6CA89CDEE0DACEC94A5E45D6910B5337343149007DE2443050D154,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105660Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-debug-l1-1-0.dllMD5=E02F6786930435C736D71E9B6B898773,SHA256=4C0F43EAC3834878F16175B17427C0195A3213B7CDF9702447667D703AA29B54,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105659Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-datetime-l1-1-1.dllMD5=78876D83AA27E510EC3DC3355D034B92,SHA256=44A696C4626AF85EA565D651D7FAF5E21B6EB0C6EE47EE93419D8A7BAD565278,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105658Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-datetime-l1-1-0.dllMD5=CF9560A4450AC70C51866581802AE8CC,SHA256=A7A23DC37F028D38D2836CE881FCFF1FD066538588B207BBBCC3B1AB96E3AB62,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105657Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-console-l1-1-0.dllMD5=893E267BD0B91FADAC2A2BAE70FD0400,SHA256=17D17AC0383117E9A14D7687ECAA3B27AF1C71B89687A5C3E5B8761B2E64EDFC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105656Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-comm-l1-1-0.dllMD5=C7EC73197892D7F63059C10D19BD5D90,SHA256=768E17ED08111FD22BAAC8FAC00C7DD87F0E57FEFCDAC58CE04B868528B2FDFC,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105655Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-core-com-l1-1-0.dllMD5=08A5A3129DCB52F3C4E51EE3C4A827E7,SHA256=3C6549832275052BCC2234CC4433D95407800ED65359F5147C4762EE0C71F712,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space 23542300x800000000000000023105654Microsoft-Windows-Sysmon/Operationalwin-host-874.attackrange.local-2021-11-18 19:33:21.287{AD5E2759-AA7F-6196-83C7-09000000F101}2008WIN-HOST-874\AdministratorC:\Windows\system32\Dism.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\B74066E8-2146-4410-A981-3C4B5B72DCBA\api-ms-win-base-util-l1-1-0.dllMD5=29CD6DDC6BADE9098B9A4402C6336D62,SHA256=B97C475AA8241C9B674E8C51C387AFAAA7977B036D9E2F7FAFB6CACC11D985BE,IMPHASH=00000000000000000000000000000000truefalse - insufficient disk space