23542300x800000000000000060272Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:38.599{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E053C75A3972766780D81FB0B9210FF2,SHA256=B1B5362778903D26DD63C6C44EF9D427C58F499F34520EA98A1A0180291F74C2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037837Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:38.003{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0539976450EBB909F60B3C750791F33D,SHA256=9F0CAD122B66231AE53EEA335DCD050762EE1785AE3C52A1AE4DA41DA0880C0F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060273Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:39.615{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5B2870E4C83FDBA21CF95E9AFE7FC72,SHA256=6EAB3E7D4FA6607581C55E7D3B7AAE3FF609DE41689C6B4E1B7E4F9398103740,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037851Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0027-60AE-4802-00000000C601}1532C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037850Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037849Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037848Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037847Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037846Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037845Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037844Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037843Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037842Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037841Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0027-60AE-4802-00000000C601}1532C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000037840Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.988{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0027-60AE-4802-00000000C601}1532C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037839Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.989{266C2353-0027-60AE-4802-00000000C601}1532C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000037838Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:39.113{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2647DF12A755B18F08F107B385A1A596,SHA256=82989BEC29968A513FA04261E1DA8F9E16BF7C727CE5230E77E7D1821A779F6A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060274Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:40.631{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6EA87B20C31E0164B779242629290B56,SHA256=77CC334DE4905518820F752A178AF6C3B9DD4D21F67DB457F8A39CF97EEDB32C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037867Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.816{266C2353-0028-60AE-4902-00000000C601}35523660C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037866Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0028-60AE-4902-00000000C601}3552C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037865Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037864Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037863Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037862Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037861Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037860Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037859Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037858Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037857Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037856Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0028-60AE-4902-00000000C601}3552C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000037855Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.660{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0028-60AE-4902-00000000C601}3552C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037854Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.661{266C2353-0028-60AE-4902-00000000C601}3552C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000037853Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.253{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D087DAB7F186B56D740EA8D608D54B8,SHA256=A3C68CFE0D65C1A53CB9735D623D857F13B50733E240CF8B67C6DBD2FD5CB9DF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037852Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:40.175{266C2353-0027-60AE-4802-00000000C601}15322960C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060284Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.849{7CDEDE96-0029-60AE-7302-00000000C501}11806068C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060283Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.724{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D323C7AB209E0E19EF2E5D988CD15F40,SHA256=B02E7C1ACA1DBFB631AD6FF81E4DF41A764CBFE979D6848F3FDB326305CA205A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037883Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.504{266C2353-0029-60AE-4A02-00000000C601}1056600C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037882Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0029-60AE-4A02-00000000C601}1056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037881Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037880Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037879Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037878Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037877Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037876Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037875Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037874Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037873Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037872Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0029-60AE-4A02-00000000C601}1056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000037871Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0029-60AE-4A02-00000000C601}1056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037870Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.333{266C2353-0029-60AE-4A02-00000000C601}1056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000037869Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.316{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC38831FA05F6A2681A3D8795C255B77,SHA256=620701B7C433CC25EE756B13BF787A77FFD751C3371C97A567483D46A619DBE4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060282Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0029-60AE-7302-00000000C501}1180C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060281Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060280Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060279Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060278Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060277Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-0029-60AE-7302-00000000C501}1180C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060276Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.505{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0029-60AE-7302-00000000C501}1180C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060275Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:41.506{7CDEDE96-0029-60AE-7302-00000000C501}1180C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000037868Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.003{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8505FBDBC3BA89CD3E2127BCADC01672,SHA256=B5E1B342BC6C0BB550583D3D6596D58E596EC0A60550B053E2DC5D588FDE5E20,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037885Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:42.507{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=953D648B61EBAFC59273195BF80254A6,SHA256=6B2B93E2DE4FAE4D91C7D11CE0E641B6A941DEECF8A0F9FB909245A4E8E906DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037884Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:42.363{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=31126593FB4C2085D75800C95AD0B6B9,SHA256=664CF52C6BC4F795C29F9B221D70A5DCC71D9B9BABA1FB2A027CAB1107B85831,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060295Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.742{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D18C594B700427067965EBE8958A8168,SHA256=BAD2FE1B2D10C068D257392CCDC44BD05D594DD1791B411EB3C947566F8841A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060294Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.554{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A8FFA4E319EB92D06A5F96A6265B06C4,SHA256=480D8E651A8C6DB1F86FCBC617CAB4AE6DAE10D5B2C8755539BDDE36B88BC559,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060293Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.554{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E0AD2757FF8236FBBCAC75862D3270C8,SHA256=EF6A4F2D0839C193EE7AE076A3DC1067C526E394A375A5EDCEBBE9E03769251F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060292Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-002A-60AE-7402-00000000C501}5932C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060291Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060290Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060289Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060288Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060287Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-002A-60AE-7402-00000000C501}5932C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060286Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.037{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-002A-60AE-7402-00000000C501}5932C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060285Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:42.038{7CDEDE96-002A-60AE-7402-00000000C501}5932C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000060305Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-002B-60AE-7502-00000000C501}4992C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060304Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060303Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060302Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060301Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060300Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-002B-60AE-7502-00000000C501}4992C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060299Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.898{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-002B-60AE-7502-00000000C501}4992C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060298Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.899{7CDEDE96-002B-60AE-7502-00000000C501}4992C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000060297Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:40.256{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50929-false10.0.1.12-8000- 23542300x800000000000000060296Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.773{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3886C74F9AFD517ED79FFFD28357DAF1,SHA256=B4E337647A7D77A40238FB0F6F9E864514AAA0F62D16C3D15C7C83B0577A99A0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037900Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:41.286{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50513-false10.0.1.12-8000- 23542300x800000000000000037899Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.460{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0F3B70F8766F87C0BEF3326F0FE0ABE5,SHA256=A47AFD6F19FDE8EA09C7AD14452602C8167A4CC48400D778FC73A8979DE4C47D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037898Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-002B-60AE-4B02-00000000C601}888C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037897Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037896Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037895Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037894Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037893Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037892Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037891Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037890Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037889Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037888Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-002B-60AE-4B02-00000000C601}888C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000037887Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.413{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-002B-60AE-4B02-00000000C601}888C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037886Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:43.414{266C2353-002B-60AE-4B02-00000000C601}888C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000060306Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:44.882{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C9AF0D4237340051AA2EEF401574A18,SHA256=00D533B1668C93809A32EC851EAFA0CAA7D132B8FABB6BB22A4ACE4750ED5F24,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037902Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:44.648{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5DDA27E326CF02390A8D106717E28290,SHA256=DFD31CD6CBA5C5BD5F12E0F10C13224B6A2A0FF8C231BA9598890A4B67F04538,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037901Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:44.460{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E0D61ECA74292A93C5CEAAC944D744F,SHA256=E03514388735CBF53DE1949F8763DE8FE4AB618A034D830D8683779123E3275B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060318Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.055{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50930-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000060317Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:43.055{7CDEDE96-F0E1-60AD-2D00-00000000C501}2484C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50930-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 23542300x800000000000000060316Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.898{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=07A4331327E47135DD755268A876B1E6,SHA256=0164EB037E33625D5ED5DAAC3D38BC41927B3FE729B89EDDFB1AAF7EFC1FEBC0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037903Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:45.476{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A90F47F626B2A4B54F3FE5C3A04B4C2,SHA256=1B7831A5187DB9FB7BFDA1C19A9086BA972883F3974352F68E962E77174FD900,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060315Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-002D-60AE-7602-00000000C501}6056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060314Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060313Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060312Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060311Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060310Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-002D-60AE-7602-00000000C501}6056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060309Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-002D-60AE-7602-00000000C501}6056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060308Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.836{7CDEDE96-002D-60AE-7602-00000000C501}6056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000060307Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:45.132{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A8FFA4E319EB92D06A5F96A6265B06C4,SHA256=480D8E651A8C6DB1F86FCBC617CAB4AE6DAE10D5B2C8755539BDDE36B88BC559,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037904Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:46.570{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1FA161E265813F091AD2A12D4D831D9D,SHA256=9559CCBA0C5190CC780D991D8AB7D3BC0389E490228A490C239B549150C207D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060329Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.867{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DB8F18A683F86B203F05FF070C2D4B2A,SHA256=8E1806E32D50ED88BDEFCEDDEBAC4F25DC6CA8A11DBBC92E0B92C5274C4B235B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060328Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.695{7CDEDE96-002E-60AE-7702-00000000C501}52566084C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060327Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-002E-60AE-7702-00000000C501}5256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060326Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060325Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060324Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060323Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060322Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-002E-60AE-7702-00000000C501}5256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060321Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.507{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-002E-60AE-7702-00000000C501}5256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060320Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.508{7CDEDE96-002E-60AE-7702-00000000C501}5256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000060319Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.117{7CDEDE96-002D-60AE-7602-00000000C501}60563660C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000037906Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:47.867{266C2353-F0DC-60AD-2300-00000000C601}2112NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037905Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:47.585{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5855DC18BA49C250200AF4EC13FF351,SHA256=E804529D560B46031475E4FA8A7119BA440FA248B26159279A6B4814EFE64F04,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060339Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.273{7CDEDE96-002F-60AE-7802-00000000C501}15086076C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060338Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-002F-60AE-7802-00000000C501}1508C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060337Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060336Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060335Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060334Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060333Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-002F-60AE-7802-00000000C501}1508C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060332Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.070{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-002F-60AE-7802-00000000C501}1508C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060331Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.071{7CDEDE96-002F-60AE-7802-00000000C501}1508C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000060330Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:47.023{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=887B0DA8E5A434A2A234B0F390D6E8C3,SHA256=922AF49F3581BCC981B9690D0660D8011F5AD9DDA39997993D0D938156E43577,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037907Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:48.820{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=302195B522450E300DFC569539E2EAB8,SHA256=BE3BF23895CB8C3E5042D8577EB12963321CE3A50BCFEBAEF1F6969E119A0D88,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060349Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0030-60AE-7902-00000000C501}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060348Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060347Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060346Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060345Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060344Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0030-60AE-7902-00000000C501}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060343Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.695{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0030-60AE-7902-00000000C501}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060342Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.696{7CDEDE96-0030-60AE-7902-00000000C501}1628C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000060341Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.148{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F60D98791B937C436465CCA61BE1964,SHA256=AF80D12E6EE444CCCEEC08DF43490EF64545D6C5600A3C84CD5934CA048BEED8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060340Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:48.070{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3E6D8D70CEE70D195F1E4E46A7990800,SHA256=F51C6FC1D698DDDB01C38D26F5A84409790A168469CA64FB8CEF286F32FBC53F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037908Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:49.835{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9931E10DCD3F6D7F8221AE374198F27,SHA256=C4825C2BFEB17FB8ACC5D3AF5B97A0D5FCEFE24C3A6BAF5BD0B444B14B76B2E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060352Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.711{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=78152CF3D5F9AF1DE260F4BD94BF3214,SHA256=512F97FDA2796A427B7A449BDD15DDCDF355E19628A031A7063F80B6B573D419,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060351Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.164{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E3AEBC6F7644ABC9820C25CB433FC26,SHA256=BAD7E2AE23C0C3E1575EB89F677CF249EB85741CFAEC91E110329566770C876B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060350Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:46.259{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50931-false10.0.1.12-8000- 23542300x800000000000000037910Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:50.851{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53C5EB968C49F51F781357CE00237089,SHA256=9A0FCF9FEA51123CCF66F7EF7636B7BC0B4A756BAA4551005CD18A8C2BB6FF7B,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000060356Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:00:50.836{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\D370F6FF-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_D370F6FF-0000-0000-0000-100000000000.XML 13241300x800000000000000060355Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:00:50.836{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\30D2AA0C-2752-4015-BD52-B163B3999E1B\Config SourceDWORD (0x00000001) 13241300x800000000000000060354Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:00:50.836{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\30D2AA0C-2752-4015-BD52-B163B3999E1B\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_30D2AA0C-2752-4015-BD52-B163B3999E1B.XML 23542300x800000000000000060353Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:50.179{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=68B51544A39385F460EE3620CD9D6728,SHA256=A090DC84D1845814C318DD8CB67F54BCDDF657BCE852C7D5315DC8328F72BD12,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037909Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:47.023{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50514-false10.0.1.12-8089- 23542300x800000000000000037912Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:51.867{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A3ABB09100EDBE5DC0AD424CCB836E96,SHA256=0CAC54B0F4083B1A10898C755E6EEFD8042FCC94A3B0F3AE06E4823DD93F7CB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060358Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:51.867{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=28C005300363305A622CDA38012F0F34,SHA256=F39F628D2EAE9283A97C4CAF040B1BEA221AB9EAEF9F492B955B7E778EE5F75A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060357Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:51.195{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50F310F5B29410927904F43386804CEF,SHA256=FD801B82B1ED831F816E7D061708B7CA695C68F4B1EB857CF5D58C70BD6CE38E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037911Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:47.181{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50515-false10.0.1.12-8000- 23542300x800000000000000037913Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:52.898{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A480022E1F99C6B047E3050FE7C3EA7,SHA256=364E31BA6FBAE3C85CF958B2F93910F69710582BC0B6AC7810EBCF88C80C274E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060364Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:52.367{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000060363Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.970{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50933-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000060362Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.970{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50933-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000060361Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.947{7CDEDE96-F0D1-60AD-0D00-00000000C501}892C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50932-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local135epmap 354300x800000000000000060360Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.947{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50932-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local135epmap 23542300x800000000000000060359Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:52.226{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FA685CD8075036FE4F353ED3A8BB80D4,SHA256=13EEA1B23E1336D707EC6FDFD249AD97E1B65F4B096677FDEC9615D295F99931,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060374Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.773{7CDEDE96-F0D1-60AD-1600-00000000C501}13242480C:\Windows\system32\svchost.exe{7CDEDE96-0035-60AE-7A02-00000000C501}2456C:\Windows\system32\DllHost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060373Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.773{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-0035-60AE-7A02-00000000C501}2456C:\Windows\system32\DllHost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060372Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.757{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-0035-60AE-7A02-00000000C501}2456C:\Windows\system32\DllHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060371Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.757{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-0035-60AE-7A02-00000000C501}2456C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060370Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.757{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0035-60AE-7A02-00000000C501}2456C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060369Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.757{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-0035-60AE-7A02-00000000C501}2456C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000060368Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.979{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50934-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000060367Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:49.979{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50934-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 23542300x800000000000000060366Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.257{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBCE36AF9CC8580EC55652991D0AD1C1,SHA256=2BA76EF4D6111C8B28C680970D2B5CF041A79CA20C8829BFF2CCB3438EE7777B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060365Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:53.242{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000037914Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:54.039{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6472E76E1A026E1C6A5955F1F28F48F3,SHA256=502FC52D1E592B7F0FB3530B5D5119186AF0AD2335CBE277C2301CBB25ADA392,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060380Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.929{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060379Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.929{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060378Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.929{7CDEDE96-F0CF-60AD-0B00-00000000C501}632684C:\Windows\system32\lsass.exe{7CDEDE96-F0CF-60AD-0A00-00000000C501}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060377Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.757{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8B69CBC1190B7995B67059D604AA9DBA,SHA256=2611CE04E4297AFF24BA709FC98A43A21A330155413B4C0B338D2D0BC729E438,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060376Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:51.351{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50935-false10.0.1.12-8000- 23542300x800000000000000060375Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.273{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84E56E883B2B1608836912AF98F709B1,SHA256=4B1262BC458F487FEF860FDA81C259DBC09BF9B1890A879DF7476E7FE1585660,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060383Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.960{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=A8659CD6E85A1A813D5982529E909902,SHA256=73291507093BE6AA3FF0469D71BCACA779233C9E2FE9AA5E1331E5F091F71F84,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060382Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.960{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=BFEDBE30AA1C1EF3C685EF7BB38023EE,SHA256=4D3C1AA85BC3B5063EC4252D3AB2B2B0C97AA5193A9EBC3C14C5F2BC569E30E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060381Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.289{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=58AF9D132631834FC289A887680D186A,SHA256=97488A124BC6071BC9555895B7656F36166423C96DB7AA58A03827EB78C9B10C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037916Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:52.367{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50516-false10.0.1.12-8000- 23542300x800000000000000037915Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:55.054{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A191DE6890BC04FAB9106674B66E4B5,SHA256=AEB448EEA0643C86A55906D5FD8EAFB9F5C92560A35E7C4D2D3AD82D5DF6342A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060389Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:56.726{7CDEDE96-F0CF-60AD-0B00-00000000C501}632684C:\Windows\system32\lsass.exe{7CDEDE96-F0B3-60AD-0100-00000000C501}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 354300x800000000000000060388Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.069{7CDEDE96-F0D1-60AD-1400-00000000C501}1084C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcptruefalse10.0.1.14win-dc-141.attackrange.local50936-false93.184.221.240-80http 354300x800000000000000060387Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.066{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51866- 354300x800000000000000060386Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.065{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58125- 354300x800000000000000060385Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:54.064{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local52657- 23542300x800000000000000060384Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:56.304{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7FF9DF7E60E20B8E490DF0249BD7617,SHA256=4A62C50FF44508A2C549D119B43FB7E82422C54F104A13D9753E108BC28EFF69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037917Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:56.070{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F815F00A5D3253774292263FE3C722D,SHA256=49F2B401538F0EAF018E2B0873E110ACD2E44BE961214F974F6C928184317D4A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060448Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.679{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41968|C:\Windows\system32\windows.cortana.Desktop.dll+16557|C:\Windows\system32\windows.cortana.Desktop.dll+12d9b|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000060447Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.679{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41680|C:\Windows\system32\windows.cortana.Desktop.dll+92dc|C:\Windows\system32\windows.cortana.Desktop.dll+12d31|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000060446Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.679{7CDEDE96-F8F3-60AD-8F01-00000000C501}45806140C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060445Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.679{7CDEDE96-F8F3-60AD-8F01-00000000C501}45806140C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060444Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.648{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D523D0744FF72605642194BB8AA05629,SHA256=EF72DB51B45853D43FA0A35BD2C85D15AA1BDF62F5C771399E3C99481834E278,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060443Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.648{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C581F9E555872BEE058566CF203E9184,SHA256=0FADC7B587DC703773906987A38AA61393113D7EA52CD000BE3C38622D82EF1A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060442Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.632{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000060441Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.632{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000060440Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.632{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805520C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b13af|C:\Windows\System32\SHELL32.dll+b3175|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060439Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.632{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805520C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b308e|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060438Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.632{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000060437Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.632{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000060436Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.617{7CDEDE96-F0E1-60AD-2B00-00000000C501}30205288C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\tileobjserver.dll+bce2|c:\windows\system32\tileobjserver.dll+26da2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 10341000x800000000000000060435Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.617{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805520C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060434Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.617{7CDEDE96-F0E1-60AD-2B00-00000000C501}30205288C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|c:\windows\system32\tileobjserver.dll+bc8f|c:\windows\system32\tileobjserver.dll+26da2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a 10341000x800000000000000060433Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060432Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060431Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060430Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060429Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060428Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060427Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060426Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060425Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}892920C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060424Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}892920C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000037918Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:57.086{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=78812F43D6B9C08455924DB9F8A84F84,SHA256=A400943F5F1550517578ED080A1885C02B0A2802EB1A754F4F168C3E56D6DB7E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060423Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060422Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060421Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060420Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060419Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060418Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060417Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}892920C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060416Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}892920C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060415Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060414Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060413Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}892920C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060412Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}892920C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060411Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060410Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060409Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a384|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060408Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+489d|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a2ed|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060407Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+489d|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a2ed|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060406Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060405Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060404Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060403Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a384|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060402Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+489d|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a2ed|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060401Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+489d|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a2ed|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060400Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060399Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060398Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060397Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060396Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060395Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804964C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060394Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F0D0-60AD-0C00-00000000C501}836620C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060393Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804964C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060392Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+57c95|C:\Windows\System32\TwinUI.dll+37528|C:\Windows\System32\TwinUI.dll+37448|C:\Windows\System32\TwinUI.dll+38893|C:\Windows\System32\TwinUI.dll+36e6d|C:\Windows\System32\TwinUI.dll+36c71|C:\Windows\System32\TwinUI.dll+10928d|C:\Windows\System32\TwinUI.dll+d211f|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+c6ae|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060391Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.601{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+57c95|C:\Windows\System32\TwinUI.dll+37590|C:\Windows\System32\TwinUI.dll+37435|C:\Windows\System32\TwinUI.dll+38893|C:\Windows\System32\TwinUI.dll+36e6d|C:\Windows\System32\TwinUI.dll+36c71|C:\Windows\System32\TwinUI.dll+10928d|C:\Windows\System32\TwinUI.dll+d211f|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+c6ae|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060390Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.382{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6829B2675E4EAA866DA6E590AF05958A,SHA256=563BC8F75FA80A924C82FAFAC66B0D5162A3DC47CB7C64A71C0521B1319F97E0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060473Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.855{7CDEDE96-F0B3-60AD-0100-00000000C501}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50939-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local445microsoft-ds 354300x800000000000000060472Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.855{7CDEDE96-F0B3-60AD-0100-00000000C501}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50939-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local445microsoft-ds 354300x800000000000000060471Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.758{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-141.attackrange.local50938-false10.0.1.14win-dc-141.attackrange.local389ldap 354300x800000000000000060470Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.758{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50938-false10.0.1.14win-dc-141.attackrange.local389ldap 354300x800000000000000060469Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.747{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50937-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000060468Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:55.747{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local50937-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 10341000x800000000000000060467Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060466Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060465Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060464Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060463Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060462Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F8F2-60AD-8601-00000000C501}10565276C:\Windows\system32\sihost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\usermgrcli.dll+1121|C:\Windows\System32\modernexecserver.dll+37dac|C:\Windows\System32\modernexecserver.dll+37d4f|C:\Windows\System32\modernexecserver.dll+375a6|C:\Windows\System32\modernexecserver.dll+1a1c4|C:\Windows\System32\modernexecserver.dll+3191d|C:\Windows\System32\modernexecserver.dll+32871|C:\Windows\System32\modernexecserver.dll+3278f|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060461Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.789{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4B4BF2117A71C8F1871D916D6DB35070,SHA256=C899CFD7B7792A4736A809AB861B151AC56C46AAE60A3E0ADD63EF97488B951E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060460Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.726{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060459Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.726{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060458Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.726{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060457Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.726{7CDEDE96-F0E1-60AD-2B00-00000000C501}30205532C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\tileobjserver.dll+bce2|c:\windows\system32\tileobjserver.dll+26da2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 10341000x800000000000000060456Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.726{7CDEDE96-F0E1-60AD-2B00-00000000C501}30205532C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|c:\windows\system32\tileobjserver.dll+bc8f|c:\windows\system32\tileobjserver.dll+26da2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a 10341000x800000000000000060455Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.445{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000060454Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.445{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 23542300x800000000000000037919Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:58.102{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=247FD2E1D7F7AE66794D4156E0A02ECF,SHA256=1918FE1248FCEA735585A0940646C89FE61A580DEAAC6DCF9A29ECDE28A3A1FA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060453Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.414{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060452Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.398{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805412C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060451Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.398{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805412C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060450Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.398{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060449Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:58.382{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060489Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.929{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=649CD0A2874DE862552AB6A0709ABE0D,SHA256=B9CED43F7F93C9E2EE449F609212FD5A12E6F368791CBD8FDA2E2D7E78AB53DA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060488Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:57.367{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50940-false10.0.1.12-8000- 23542300x800000000000000037920Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:59.117{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84AB044410E7B117788A9CD632EB5928,SHA256=2D9CF47941C536AFC02AAEF44911FEEC41F945BB1B4BE5B4AD684E84EBD1AB6F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060487Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060486Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060485Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060484Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060483Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060482Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060481Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060480Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060479Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060478Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060477Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060476Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060475Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060474Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:00:59.445{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060512Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.929{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E765B68CC29BD07B13C6EB1A0E547599,SHA256=38BD72F612D52A045925BE098B5000F2AD0958F16842E50D6226E1741743E3CD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037922Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:00:58.398{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50517-false10.0.1.12-8000- 23542300x800000000000000037921Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:00.133{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18B496B6421AB0AC0845B10BA761AE3F,SHA256=25CD802281643B919395CC195F1850FDEDB46CB9F76E9CA3803A0A604AFE03CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060511Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.258{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=A8659CD6E85A1A813D5982529E909902,SHA256=73291507093BE6AA3FF0469D71BCACA779233C9E2FE9AA5E1331E5F091F71F84,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060510Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.210{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003C-60AE-7B02-00000000C501}5440C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+5122|C:\Program Files\Mozilla Firefox\firefox.exe+10f9|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060509Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.179{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060508Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.164{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060507Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.164{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060506Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.117{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060505Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.117{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060504Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.117{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060503Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.117{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060502Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.101{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060501Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.101{7CDEDE96-003C-60AE-7B02-00000000C501}54403136C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+1845f|C:\Program Files\Mozilla Firefox\firefox.exe+661c|C:\Program Files\Mozilla Firefox\firefox.exe+10f9|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060500Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.107{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542MediumMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-003C-60AE-7B02-00000000C501}5440C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" 10341000x800000000000000060499Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.101{7CDEDE96-003C-60AE-7B02-00000000C501}54403136C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+5122|C:\Program Files\Mozilla Firefox\firefox.exe+10f9|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060498Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.054{7CDEDE96-F0D1-60AD-1200-00000000C501}4042936C:\Windows\System32\svchost.exe{7CDEDE96-003C-60AE-7B02-00000000C501}5440C:\Program Files\Mozilla Firefox\firefox.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\pcasvc.dll+52e4|c:\windows\system32\pcasvc.dll+58a9|c:\windows\system32\pcasvc.dll+5b49|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060497Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.054{7CDEDE96-F0D1-60AD-1200-00000000C501}4042936C:\Windows\System32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1440C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\pcasvc.dll+5bab|c:\windows\system32\pcasvc.dll+5b07|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060496Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.023{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-003C-60AE-7B02-00000000C501}5440C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060495Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.023{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060494Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.023{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060493Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.023{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804560C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7B02-00000000C501}5440C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\windows.storage.dll+16e61f|C:\Windows\System32\windows.storage.dll+16e295|C:\Windows\System32\windows.storage.dll+16dd86|C:\Windows\System32\windows.storage.dll+16f1f8|C:\Windows\System32\windows.storage.dll+16dbae|C:\Windows\System32\windows.storage.dll+fd025|C:\Windows\System32\windows.storage.dll+fd3a4|C:\Windows\System32\windows.storage.dll+fc9e0|C:\Windows\System32\windows.storage.dll+1664ae|C:\Windows\System32\windows.storage.dll+1661a2|C:\Windows\System32\SHELL32.dll+90ee1|C:\Windows\System32\SHELL32.dll+8fd46|C:\Windows\System32\SHELL32.dll+d0c11|C:\Windows\System32\SHELL32.dll+b6e2e|C:\Windows\System32\windows.storage.dll+2d1a2|C:\Windows\System32\windows.storage.dll+2ce99|C:\Windows\System32\windows.storage.dll+2cd6f|C:\Windows\System32\SHELL32.dll+d0c97|C:\Windows\System32\SHELL32.dll+b6e2e|C:\Windows\System32\SHELL32.dll+18d33c 10341000x800000000000000060492Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.023{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060491Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.023{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060490Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:00.020{7CDEDE96-003C-60AE-7B02-00000000C501}5440C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542HighMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\explorer.exeC:\Windows\Explorer.EXE /NOUACCHECK 10341000x800000000000000060518Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.976{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060517Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.976{7CDEDE96-F0D1-60AD-1600-00000000C501}1324708C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060516Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.976{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060515Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.960{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1673102CFCAAF4B908BAFDDB974A23AD,SHA256=EC8D1E153B33455196E03F029D84C83B1461D26DE714E94DEB2913BF55180F3D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037923Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:01.149{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AB5A7661EA3D6DF9D8B923C88A55560,SHA256=B29F90AA2513153447CF2FC7F54CE0528CCDB343B8FB5C14966C9823A1E8F900,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060514Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.226{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=38F3E08EAEA130DC9F405C657E6BC569,SHA256=B2CB88D5E1469FEDE55A5C796068E720F769B964AD15F2F3F632DA4199AE27D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060513Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.054{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=C44CFAA1E0BC1118B283C368D87C2649,SHA256=67FEDB967D8B1F118AEE544B40965FCB0655A89FA9C4882B12F4688AE2FE84A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037924Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:02.164{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8791BD7219FD2A53638EE144F9DF8BBF,SHA256=2943BCC2E8644B3B19D80F1505CDE6E9EAC5261B7CC92B3CDC88312C4DE52227,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060642Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.997{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1213abc|C:\Program Files\Mozilla Firefox\xul.dll+1321d41|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f5cf|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060641Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.995{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060640Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.995{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060639Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.981{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+1c51834|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+1bf469|UNKNOWN(0000006582161E84) 10341000x800000000000000060638Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.980{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+1c51834|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+1bf469|UNKNOWN(0000006582161E84) 10341000x800000000000000060637Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.979{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+1c51834|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+17feb9|UNKNOWN(0000006582163DFF) 10341000x800000000000000060636Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.978{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+1c51834|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+f8c2a|C:\Program Files\Mozilla Firefox\xul.dll+3b83438|C:\Program Files\Mozilla Firefox\xul.dll+14d181|C:\Program Files\Mozilla Firefox\xul.dll+14d0d8|C:\Program Files\Mozilla Firefox\xul.dll+1480e6c|C:\Program Files\Mozilla Firefox\xul.dll+144ed8|C:\Program Files\Mozilla Firefox\xul.dll+19b9371|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+157902|C:\Program Files\Mozilla Firefox\xul.dll+2ae974|C:\Program Files\Mozilla Firefox\xul.dll+3b6710c|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d 23542300x800000000000000060635Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.976{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C9CD4901A8861B8C870F652B4F28646,SHA256=846EA8D8F3DAE98274572D398C4774C73BE35265E9D0208CD6C98626DA67606D,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060634Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.12.14818892C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060633Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.11.17843883C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060632Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.10.58023599C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060631Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.8.52067545C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060630Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.9.151740711C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060629Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.7.136562732C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060628Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.951{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4384.3.140404327C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060627Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.951{7CDEDE96-003E-60AE-7F02-00000000C501}4384\chrome.4384.3.140404327C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060626Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.920{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060625Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.920{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060624Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.904{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E316100C5B017C4EC9B738603725B890,SHA256=07F36C7891F9DCE96CA7FE63DDE4A140FF20EE024EF9797E28FFF64690E9C5ED,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060623Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.904{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4384.2.23818579C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060622Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.904{7CDEDE96-003E-60AE-7F02-00000000C501}4384\chrome.4384.2.23818579C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060621Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.904{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4384.1.124995953C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060620Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.904{7CDEDE96-003E-60AE-7F02-00000000C501}4384\chrome.4384.1.124995953C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060619Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.888{7CDEDE96-003E-60AE-7F02-00000000C501}4384\chrome.4384.0.83201898C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060618Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.888{7CDEDE96-003E-60AE-7F02-00000000C501}4384\chrome.4384.0.83201898C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060617Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.888{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060616Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.888{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060615Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.873{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2c2935b|C:\Program Files\Mozilla Firefox\xul.dll+2c292d9|C:\Program Files\Mozilla Firefox\xul.dll+2ced2b6|C:\Program Files\Mozilla Firefox\xul.dll+2ceac59|C:\Program Files\Mozilla Firefox\xul.dll+2ce9384 10341000x800000000000000060614Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.873{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000060613Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.857{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+12e04b9|C:\Program Files\Mozilla Firefox\xul.dll+2a4a554|C:\Program Files\Mozilla Firefox\xul.dll+12bbafb|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+d9aecc|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+da7079|C:\Program Files\Mozilla Firefox\xul.dll+2ce7f2d|C:\Program Files\Mozilla Firefox\xul.dll+2ce9f80|C:\Program Files\Mozilla Firefox\xul.dll+2ce9384|C:\Program Files\Mozilla Firefox\xul.dll+2ce1c04|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Program Files\Mozilla Firefox\xul.dll+3d1c3c|C:\Program Files\Mozilla Firefox\xul.dll+3fda6|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e 18141800x800000000000000060612Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.857{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-0C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060611Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.857{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-0C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060610Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.841{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060609Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.841{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060608Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.841{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.6.172858662C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060607Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.841{7CDEDE96-003C-60AE-7C02-00000000C501}41405544C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+2aef3b|C:\Program Files\Mozilla Firefox\xul.dll+3aa266d|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060606Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.841{7CDEDE96-003C-60AE-7C02-00000000C501}4140\gecko-crash-server-pipe.4140C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060605Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.826{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 17141700x800000000000000060604Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.12.14818892C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060603Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8403191013994A557EC92D40224613D2,SHA256=4474973B7E672B1DD0E1BAC6116F9BB6C9A6AD656AB13C5BF6190D82797F1A88,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060602Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.810{7CDEDE96-003E-60AE-7E02-00000000C501}5700\chrome.5700.0.74454471C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060601Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.11.17843883C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060600Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003E-60AE-7E02-00000000C501}5700\chrome.5700.0.74454471C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060599Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306841|C:\Program Files\Mozilla Firefox\xul.dll+187cee1|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4 17141700x800000000000000060598Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.10.58023599C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060597Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306741|C:\Program Files\Mozilla Firefox\xul.dll+187ccfe|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4 17141700x800000000000000060596Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.9.151740711C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060595Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306641|C:\Program Files\Mozilla Firefox\xul.dll+187cb44|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4 17141700x800000000000000060594Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.8.52067545C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060593Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306541|C:\Program Files\Mozilla Firefox\xul.dll+187c985|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4 17141700x800000000000000060592Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.7.136562732C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060591Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x2200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+506f1|C:\Program Files\Mozilla Firefox\xul.dll+2a65add|C:\Program Files\Mozilla Firefox\xul.dll+2a5f4d9|C:\Program Files\Mozilla Firefox\xul.dll+2a3e48d|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e|C:\Program Files\Mozilla Firefox\xul.dll+3b55728|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060590Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12af2c2|C:\Program Files\Mozilla Firefox\xul.dll+14855cd|C:\Program Files\Mozilla Firefox\xul.dll+2a3e43d|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e 10341000x800000000000000060589Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4 10341000x800000000000000060588Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+2a3e130|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e|C:\Program Files\Mozilla Firefox\xul.dll+3b55728 10341000x800000000000000060587Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.810{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+2a3e125|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e 10341000x800000000000000060586Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+2a3e0a2|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e|C:\Program Files\Mozilla Firefox\xul.dll+3b55728|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+10b21e 10341000x800000000000000060585Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-003C-60AE-7C02-00000000C501}41402660C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+121aacf|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+20088|C:\Program Files\Mozilla Firefox\xul.dll+11f5c88|C:\Program Files\Mozilla Firefox\xul.dll+1f4a5|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+1e9ef|C:\Program Files\Mozilla Firefox\xul.dll+11f6a01|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060584Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060583Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060582Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060581Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060580Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-F8F0-60AD-7E01-00000000C501}13363908C:\Windows\system32\csrss.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060579Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.795{7CDEDE96-003C-60AE-7C02-00000000C501}41405676C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+1845f|C:\Program Files\Mozilla Firefox\firefox.exe+432db|C:\Program Files\Mozilla Firefox\firefox.exe+247e8|C:\Program Files\Mozilla Firefox\xul.dll+cf875a|C:\Program Files\Mozilla Firefox\xul.dll+1211234|C:\Program Files\Mozilla Firefox\xul.dll+120f4b2|C:\Program Files\Mozilla Firefox\xul.dll+121beae|C:\Program Files\Mozilla Firefox\xul.dll+da0e64|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f69a|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060578Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.794{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4140.6.1728586627\2045876438" -childID 1 -isForBrowser -prefsHandle 2076 -prefMapHandle 2072 -prefsLen 388 -prefMapSize 238570 -parentBuildID 20210504152106 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4140 "\\.\pipe\gecko-crash-server-pipe.4140" 2088 tabC:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542LowMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" 17141700x800000000000000060577Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.779{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.6.172858662C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060576Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.779{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c95118|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6 10341000x800000000000000060575Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.779{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c950f1|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6 10341000x800000000000000060574Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.779{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c950c6|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+5555f6|C:\Program Files\Mozilla Firefox\xul.dll+797bce|C:\Program Files\Mozilla Firefox\xul.dll+21272d6 18141800x800000000000000060573Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.779{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.5.38884302C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060572Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.779{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.4.78649867C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060571Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+13060ff|C:\Program Files\Mozilla Firefox\xul.dll+187b496|C:\Program Files\Mozilla Firefox\xul.dll+589acf|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005 17141700x800000000000000060570Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.5.38884302C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060569Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1305f5f|C:\Program Files\Mozilla Firefox\xul.dll+187b2f1|C:\Program Files\Mozilla Firefox\xul.dll+589ac7|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005 17141700x800000000000000060568Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.4.78649867C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060567Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.3.139241394C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060566Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1305dbf|C:\Program Files\Mozilla Firefox\xul.dll+187b0ea|C:\Program Files\Mozilla Firefox\xul.dll+589abf|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005 17141700x800000000000000060565Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.763{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.3.139241394C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060564Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.685{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\sessionCheckpoints.jsonMD5=362985746D24DBB2B166089F30CD1BB7,SHA256=B779351C8C6B04CF1D260C5E76FB4ECF4B74454CC6215A43EA15A223BF5BDD7E,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060563Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.576{7CDEDE96-003E-60AE-7E02-00000000C501}5700\chrome.4140.1.52157975C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060562Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.476{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060561Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.445{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12cd198|C:\Program Files\Mozilla Firefox\xul.dll+1305e8f|C:\Program Files\Mozilla Firefox\xul.dll+187b67b|C:\Program Files\Mozilla Firefox\xul.dll+1879df6|C:\Program Files\Mozilla Firefox\xul.dll+118df94|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+da7079|C:\Program Files\Mozilla Firefox\xul.dll+2ce7f2d|C:\Program Files\Mozilla Firefox\xul.dll+2ce9f80|C:\Program Files\Mozilla Firefox\xul.dll+2ce9384|C:\Program Files\Mozilla Firefox\xul.dll+2ce1c04|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Program Files\Mozilla Firefox\xul.dll+3d1c3c|C:\Program Files\Mozilla Firefox\xul.dll+3fda6|C:\Program Files\Mozilla Firefox\xul.dll+1224921|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e 18141800x800000000000000060560Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.445{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.2.1923903C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060559Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.445{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.2.1923903C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060558Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.445{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.1.52157975C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060557Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.382{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060556Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.382{7CDEDE96-F0D1-60AD-1600-00000000C501}13242480C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060555Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.382{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060554Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.382{7CDEDE96-003E-60AE-7E02-00000000C501}5700\chrome.4140.0.38292229C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060553Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.367{7CDEDE96-003C-60AE-7C02-00000000C501}41405544C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+2aef3b|C:\Program Files\Mozilla Firefox\xul.dll+3aa266d|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060552Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:02.367{7CDEDE96-003E-60AE-7E02-00000000C501}5700\gecko-crash-server-pipe.4140C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060551Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.335{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003E-60AE-7D02-00000000C501}5712C:\Windows\system32\wbem\wmiprvse.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060550Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.335{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003E-60AE-7D02-00000000C501}5712C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060549Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.320{7CDEDE96-F0D1-60AD-1600-00000000C501}13244900C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7D02-00000000C501}5712C:\Windows\system32\wbem\wmiprvse.exe0x101541C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+20fee|C:\Windows\system32\wbem\wmiprvsd.dll+43f7|C:\Windows\system32\wbem\wmiprvsd.dll+15538|C:\Windows\system32\wbem\wmiprvsd.dll+1498a|C:\Windows\system32\wbem\wmiprvsd.dll+146e6|C:\Windows\system32\wbem\wmiprvsd.dll+140fe|C:\Windows\system32\wbem\wbemcore.dll+b920|C:\Windows\system32\wbem\wbemcore.dll+255ff|C:\Windows\system32\wbem\wbemcore.dll+24a9a|C:\Windows\system32\wbem\wbemcore.dll+2485e|C:\Windows\system32\wbem\wbemcore.dll+2685b|C:\Windows\system32\wbem\wbemcore.dll+22b78|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060548Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.289{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7D02-00000000C501}5712C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060547Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.273{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\26253MD5=5B7656744B8326EB674AD9E2DD35D1E3,SHA256=4D58AD142E362162E69EAF42B66E26F3C98A75E8A4838F671660D3A702BA0E26,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060546Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.273{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\cookies.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060545Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.257{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805520C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060544Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.242{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804660C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+1e03a|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060543Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.242{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804660C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\Explorer.EXE+1f054|C:\Windows\Explorer.EXE+1f000|C:\Windows\Explorer.EXE+1dfec|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060542Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.242{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b2a80|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060541Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.242{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060540Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.195{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060539Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.195{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060538Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-003C-60AE-7C02-00000000C501}41402660C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+121aacf|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+20088|C:\Program Files\Mozilla Firefox\xul.dll+11f5c88|C:\Program Files\Mozilla Firefox\xul.dll+1f4a5|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+1e9ef|C:\Program Files\Mozilla Firefox\xul.dll+11f6a01|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060537Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060536Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060535Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060534Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060533Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060532Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-003C-60AE-7C02-00000000C501}41405676C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\Mozilla Firefox\xul.dll+2667e4|C:\Program Files\Mozilla Firefox\xul.dll+12110b9|C:\Program Files\Mozilla Firefox\xul.dll+120f4b2|C:\Program Files\Mozilla Firefox\xul.dll+121beae|C:\Program Files\Mozilla Firefox\xul.dll+da0e64|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f69a|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060531Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.179{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4140.0.382922295\2058942629" -parentBuildID 20210504152106 -prefsHandle 1400 -prefMapHandle 1392 -prefsLen 1 -prefMapSize 238570 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4140 "\\.\pipe\gecko-crash-server-pipe.4140" 1496 gpuC:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542MediumMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" 17141700x800000000000000060530Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.164{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.0.38292229C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060529Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:02.164{7CDEDE96-003C-60AE-7C02-00000000C501}4140\gecko-crash-server-pipe.4140C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060528Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.132{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060527Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.132{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060526Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.132{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060525Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.132{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060524Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.117{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-003E-60AE-7D02-00000000C501}5712C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060523Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.117{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7D02-00000000C501}5712C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060522Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.101{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060521Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.101{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060520Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.101{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060519Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.992{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\parent.lockMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060853Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.986{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F972FB8B915660DD5245D13BD34D8E9,SHA256=5551F6B674B2B817237F4C59F03F88D9616D0E9ACDD966AD6F46FC02AB03F90F,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060852Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.986{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5944.2.122820601C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060851Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.986{7CDEDE96-003F-60AE-8102-00000000C501}5944\chrome.5944.2.122820601C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060850Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.986{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5944.1.147665544C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060849Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.986{7CDEDE96-003F-60AE-8102-00000000C501}5944\chrome.5944.1.147665544C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060848Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.986{7CDEDE96-003F-60AE-8102-00000000C501}5944\chrome.5944.0.53722994C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060847Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.986{7CDEDE96-003F-60AE-8102-00000000C501}5944\chrome.5944.0.53722994C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060846Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.986{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060845Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.986{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000037925Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:03.167{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A62FDC152C71DD1F7E5DDFB17E6E7CC,SHA256=68B2F44C005C6302EDE9E16E5827947B33AD4D078EDA920AAD6E6BC2B9D4BA46,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060844Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.955{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+12e04b9|C:\Program Files\Mozilla Firefox\xul.dll+2a4a554|C:\Program Files\Mozilla Firefox\xul.dll+12bbafb|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+d9aecc|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d|C:\Program Files\Mozilla Firefox\xul.dll+15d48a 18141800x800000000000000060843Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.955{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-2C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060842Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.955{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-2C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060841Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.940{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060840Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.940{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060839Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.940{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.20.26226562C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060838Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.940{7CDEDE96-003C-60AE-7C02-00000000C501}41405544C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+2aef3b|C:\Program Files\Mozilla Firefox\xul.dll+3aa266d|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060837Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.940{7CDEDE96-003C-60AE-7C02-00000000C501}4140\gecko-crash-server-pipe.4140C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060836Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.928{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED1B748065DBEA0C39D884502D85BB14,SHA256=68699130A4E12264E9E47941132330D4ABC63718F9A8D5204469B765BBD36779,IMPHASH=00000000000000000000000000000000falsetrue 17141700x800000000000000060835Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.908{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.26.207076697C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060834Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.908{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.25.152345061C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060833Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.908{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306841|C:\Program Files\Mozilla Firefox\xul.dll+187cee1|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 17141700x800000000000000060832Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.908{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.24.16867283C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060831Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306741|C:\Program Files\Mozilla Firefox\xul.dll+187ccfe|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 17141700x800000000000000060830Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.23.38559805C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060829Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306641|C:\Program Files\Mozilla Firefox\xul.dll+187cb44|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 17141700x800000000000000060828Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.22.188455463C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060827Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306541|C:\Program Files\Mozilla Firefox\xul.dll+187c985|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 17141700x800000000000000060826Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.21.163185724C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060825Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x2200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+506f1|C:\Program Files\Mozilla Firefox\xul.dll+2a65add|C:\Program Files\Mozilla Firefox\xul.dll+2a5f4d9|C:\Program Files\Mozilla Firefox\xul.dll+2a3e48d|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d|C:\Program Files\Mozilla Firefox\xul.dll+15d48a|C:\Program Files\Mozilla Firefox\xul.dll+4f91189 10341000x800000000000000060824Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12af2c2|C:\Program Files\Mozilla Firefox\xul.dll+14855cd|C:\Program Files\Mozilla Firefox\xul.dll+2a3e43d|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d 10341000x800000000000000060823Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.907{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060822Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060821Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060820Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060819Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060818Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060817Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060816Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060815Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060814Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060813Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060812Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060811Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.906{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060810Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.905{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+2a3e130|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d|C:\Program Files\Mozilla Firefox\xul.dll+15d48a 10341000x800000000000000060809Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.905{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+2a3e0a2|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d|C:\Program Files\Mozilla Firefox\xul.dll+15d48a|C:\Program Files\Mozilla Firefox\xul.dll+4f91189|C:\Program Files\Mozilla Firefox\xul.dll+4f91132 10341000x800000000000000060808Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-003C-60AE-7C02-00000000C501}41402660C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+121aacf|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+20088|C:\Program Files\Mozilla Firefox\xul.dll+11f5c88|C:\Program Files\Mozilla Firefox\xul.dll+1f4a5|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+1e9ef|C:\Program Files\Mozilla Firefox\xul.dll+11f6a01|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060807Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060806Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060805Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060804Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060803Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060802Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.887{7CDEDE96-003C-60AE-7C02-00000000C501}41405676C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+1845f|C:\Program Files\Mozilla Firefox\firefox.exe+432db|C:\Program Files\Mozilla Firefox\firefox.exe+247e8|C:\Program Files\Mozilla Firefox\xul.dll+cf875a|C:\Program Files\Mozilla Firefox\xul.dll+1211234|C:\Program Files\Mozilla Firefox\xul.dll+120f4b2|C:\Program Files\Mozilla Firefox\xul.dll+121beae|C:\Program Files\Mozilla Firefox\xul.dll+da0e64|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f69a|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060801Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.895{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4140.20.262265629\1095847731" -childID 3 -isForBrowser -prefsHandle 4460 -prefMapHandle 4404 -prefsLen 6140 -prefMapSize 238570 -parentBuildID 20210504152106 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4140 "\\.\pipe\gecko-crash-server-pipe.4140" 4488 tabC:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542LowMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" 17141700x800000000000000060800Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.887{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.20.26226562C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060799Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.840{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C93D8E2435BCF0196C3E9D94C5CED6C4,SHA256=E71789FA2187B8B8DBEAF70FDF857DF206CF153099DF650B6A21A367F3BBE45F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060798Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.808{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=6CBE80E6D2BFD3D8B6D27B8E9D1E3EF5,SHA256=94A1DEEA8F4EC75A4EE1B0B7241A544313F7FF755FFCE76CF269AECB2E2BA2B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060797Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.808{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=982076E7C856A73E2C8A3F9928048429,SHA256=5398255AEF8037F0F4B1940809A2F122AE1B7CAFE1C178129E49A1C8DDB94B87,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060796Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.808{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=E3F5CFCC4BC76574B4C526B53FEFCDE1,SHA256=36C20AB36170C84C143B62EE2F357537E35ADDC0A5662E46C774BF435BC63D7F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060795Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.807{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=F3EA5A8E8C8AF083E30556EAEA48774B,SHA256=136C4DEE0F557ED438AED4EBB081ED416A57E321168CD5496FE2EEAC0323FA52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060794Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.806{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=2A2B104038AA5D1E254B309D6DB8F887,SHA256=D1AD450E3E055B95C6E0393ED4FEDB0A42F5CDE6F8000A103B3850938CFFE56D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060793Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.804{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=6CAB3049D88437ABF63423EFC50AB7BA,SHA256=ECA47E93AECDF0924F090554E43A950F9A3EF31BBA9138BC8AE4B71117598E77,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060792Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.803{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=B25683EEE47176954A19155E9F34BBBF,SHA256=3F7113CA2650AC5AC19DDC783B870514FB31867C2282337735151B2D88180064,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060791Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=0C0AEC3B990F2B1EDAB996A819BF19B4,SHA256=D05BF6ED8FB8C23A08FB888EDEBF031C7D79BD4D6FCED66AD1AAE0710F9A2382,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060790Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=AE81CF74C5EAD7304CB6035BA930579D,SHA256=78286C418AF5D97AF07654A5D370D377BC32582B6E064D164B4AD093CF1FB2DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060789Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=357B8202907E6614FFF5C40766083B81,SHA256=06D13BF645F28FA352ACD5EFAC0D9727D09E595B26495522F542CE98EF9735CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060788Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=585B66370C6DE3CA8690D60CA28A2666,SHA256=C4D52FB4BC8BB5148BB42E568BE6F3E0E31CA869F0C4B9E15877701FB220B90E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060787Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=02CCAE4EE57E1242455C5E322A252ED9,SHA256=9690E4DDD43DC4F40D4A2B9F68570CFB7311559CFAEBA3F4892688CAB9C7B4A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060786Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=60B54EA9EFB68A2AE33C50290CF6416F,SHA256=DF8A5624D09B5880F79B1B24F06EB4DF1070A07351262DA21C2E947C5AEBE1D2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060785Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41950|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d|C:\Program Files\Mozilla Firefox\xul.dll+15d48a|C:\Program Files\Mozilla Firefox\xul.dll+4f91189|C:\Program Files\Mozilla Firefox\xul.dll+4f91132 23542300x800000000000000060784Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=EA101C70C874AFF3A60B92F97D3EFE84,SHA256=21C1D9D10ADDB55691DBBEE98FC40405155522FFF87F92A58DD056FCD74AE21C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060783Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.787{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41950|C:\Program Files\Mozilla Firefox\xul.dll+6a91b|C:\Program Files\Mozilla Firefox\xul.dll+382d564|C:\Program Files\Mozilla Firefox\xul.dll+3a830bf|C:\Program Files\Mozilla Firefox\xul.dll+3a8043a|C:\Program Files\Mozilla Firefox\xul.dll+4f91132|C:\Program Files\Mozilla Firefox\xul.dll+14bd531|C:\Program Files\Mozilla Firefox\xul.dll+14bf3c3|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+14b953d|C:\Program Files\Mozilla Firefox\xul.dll+15d48a|C:\Program Files\Mozilla Firefox\xul.dll+4f91189|C:\Program Files\Mozilla Firefox\xul.dll+4f91132 354300x800000000000000060782Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcpfalsefalse127.0.0.1-50942-false127.0.0.1-50941- 354300x800000000000000060781Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:01.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse127.0.0.1-50942-false127.0.0.1-50941- 10341000x800000000000000060780Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060779Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060778Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060777Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060776Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060775Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-F8F2-60AD-8601-00000000C501}10565276C:\Windows\system32\sihost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\usermgrcli.dll+1121|C:\Windows\System32\modernexecserver.dll+37dac|C:\Windows\System32\modernexecserver.dll+37d4f|C:\Windows\System32\modernexecserver.dll+375a6|C:\Windows\System32\modernexecserver.dll+1a1c4|C:\Windows\System32\modernexecserver.dll+3191d|C:\Windows\System32\modernexecserver.dll+32871|C:\Windows\System32\modernexecserver.dll+3278f|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060774Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.724{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060773Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.687{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2c2935b|C:\Program Files\Mozilla Firefox\xul.dll+2c292d9|C:\Program Files\Mozilla Firefox\xul.dll+2ced2b6|C:\Program Files\Mozilla Firefox\xul.dll+2ceac59|C:\Program Files\Mozilla Firefox\xul.dll+2ce9384 10341000x800000000000000060772Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060771Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060770Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000060769Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.687{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000060768Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.671{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805520C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060767Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.656{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c95118|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+73369f|C:\Program Files\Mozilla Firefox\xul.dll+7333fd|C:\Program Files\Mozilla Firefox\xul.dll+20cce85|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e|C:\Program Files\Mozilla Firefox\xul.dll+3b55728|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+17feb9|UNKNOWN(0000006582163DFF) 10341000x800000000000000060766Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.656{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c950f1|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+73369f|C:\Program Files\Mozilla Firefox\xul.dll+7333fd|C:\Program Files\Mozilla Firefox\xul.dll+20cce85|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e|C:\Program Files\Mozilla Firefox\xul.dll+3b55728|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+17feb9|UNKNOWN(0000006582163DFF) 10341000x800000000000000060765Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.656{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c950c6|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+73369f|C:\Program Files\Mozilla Firefox\xul.dll+7333fd|C:\Program Files\Mozilla Firefox\xul.dll+20cce85|C:\Program Files\Mozilla Firefox\xul.dll+27c6ad|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+10b21e|C:\Program Files\Mozilla Firefox\xul.dll+3b55728|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+17feb9|UNKNOWN(0000006582163DFF) 23542300x800000000000000060764Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.624{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060763Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.509{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060762Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.505{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060761Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.487{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F10CB9434D5C6AC763D17BF6441A86D5,SHA256=BC4E578C9729B0A2375F7557D12D999EB2CD3DD788165401F5F9CC1F6A1A0616,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060760Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.456{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060759Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.456{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060758Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.456{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060757Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.440{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+1422e28|C:\Program Files\Mozilla Firefox\xul.dll+121cc81|C:\Program Files\Mozilla Firefox\xul.dll+1212cda|C:\Program Files\Mozilla Firefox\xul.dll+2442fd4|C:\Program Files\Mozilla Firefox\xul.dll+1396010|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f5cf|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060756Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.440{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+1422e28|C:\Program Files\Mozilla Firefox\xul.dll+121cc81|C:\Program Files\Mozilla Firefox\xul.dll+1212cda|C:\Program Files\Mozilla Firefox\xul.dll+2442fd4|C:\Program Files\Mozilla Firefox\xul.dll+1396010|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f5cf|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060755Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.440{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=376B729C53C1EEB8ADD4C5AF5F1D68C8,SHA256=820DBB0FF4F9ED9649130CA532B994A34F7F3F54E32C99748E284FD5EF179C66,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060754Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060753Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060752Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060751Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060750Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060749Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060748Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060747Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060746Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060745Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.425{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060744Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060743Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060742Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060741Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060740Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060739Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060738Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060737Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060736Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060735Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060734Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060733Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.409{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060732Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060731Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060730Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060729Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060728Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060727Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060726Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060725Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060724Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060723Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060722Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060721Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060720Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060719Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.372{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060718Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.372{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060717Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.372{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060716Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.372{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060715Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.372{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060714Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.372{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+3d1453|C:\Program Files\Mozilla Firefox\xul.dll+e10105|C:\Program Files\Mozilla Firefox\xul.dll+e0fac1|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+41784|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000060713Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.356{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+1362869|C:\Program Files\Mozilla Firefox\xul.dll+114feb2|C:\Program Files\Mozilla Firefox\xul.dll+d9ec8a|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060712Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.340{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060711Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.340{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060710Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.325{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1213abc|C:\Program Files\Mozilla Firefox\xul.dll+1321d41|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f5cf|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060709Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.18.125160439C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060708Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.19.112568303C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060707Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.17.38519477C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060706Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.15.130418905C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060705Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.16.24886141C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060704Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.14.45680149C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060703Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060702Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4544.3.186754463C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060701Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.309{7CDEDE96-003F-60AE-8002-00000000C501}4544\chrome.4544.3.186754463C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060700Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.309{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060699Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.309{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060698Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.308{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060697Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.287{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060696Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.287{7CDEDE96-003C-60AE-7C02-00000000C501}41404852C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060695Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.287{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4544.2.127362156C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060694Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.287{7CDEDE96-003F-60AE-8002-00000000C501}4544\chrome.4544.2.127362156C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060693Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.287{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4544.1.202883786C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060692Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.287{7CDEDE96-003F-60AE-8002-00000000C501}4544\chrome.4544.1.202883786C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060691Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.287{7CDEDE96-003F-60AE-8002-00000000C501}4544\chrome.4544.0.212814795C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060690Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.287{7CDEDE96-003F-60AE-8002-00000000C501}4544\chrome.4544.0.212814795C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060689Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.287{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060688Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.287{7CDEDE96-F0CF-60AD-0B00-00000000C501}632676C:\Windows\system32\lsass.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060687Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.271{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060686Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.256{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+12e04b9|C:\Program Files\Mozilla Firefox\xul.dll+2a4a554|C:\Program Files\Mozilla Firefox\xul.dll+12bbafb|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+d9aecc|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000060685Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.256{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-1C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060684Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.256{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-1C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060683Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.256{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+1c51834|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+2c182c|C:\Program Files\Mozilla Firefox\xul.dll+2f1622|C:\Program Files\Mozilla Firefox\xul.dll+46fcd7e|UNKNOWN(0000006582164AE0) 10341000x800000000000000060682Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.256{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7F02-00000000C501}4384C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+484ecb|C:\Program Files\Mozilla Firefox\xul.dll+1c51834|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061|C:\Program Files\Mozilla Firefox\xul.dll+2c182c|C:\Program Files\Mozilla Firefox\xul.dll+2f1622|C:\Program Files\Mozilla Firefox\xul.dll+46fcd7e|UNKNOWN(0000006582164AE0) 10341000x800000000000000060681Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.240{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060680Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.240{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060679Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.240{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.13.76917780C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060678Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.240{7CDEDE96-003C-60AE-7C02-00000000C501}41405544C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+2aef3b|C:\Program Files\Mozilla Firefox\xul.dll+3aa266d|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060677Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.240{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3520FC0DC7C72D3006E8F448BBBA40E8,SHA256=616B973948101C20B9E2FDE98ABAF53A19190479C02AAEB4AD959DA6C5FCE1B9,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000060676Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:03.240{7CDEDE96-003C-60AE-7C02-00000000C501}4140\gecko-crash-server-pipe.4140C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060675Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.19.112568303C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000060674Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.18.125160439C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060673Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306841|C:\Program Files\Mozilla Firefox\xul.dll+187cee1|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac 17141700x800000000000000060672Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.17.38519477C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060671Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306741|C:\Program Files\Mozilla Firefox\xul.dll+187ccfe|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac 17141700x800000000000000060670Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.16.24886141C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060669Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306641|C:\Program Files\Mozilla Firefox\xul.dll+187cb44|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac 17141700x800000000000000060668Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.15.130418905C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060667Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306541|C:\Program Files\Mozilla Firefox\xul.dll+187c985|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac 17141700x800000000000000060666Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.14.45680149C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060665Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x2200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+506f1|C:\Program Files\Mozilla Firefox\xul.dll+2a65add|C:\Program Files\Mozilla Firefox\xul.dll+2a5f4d9|C:\Program Files\Mozilla Firefox\xul.dll+2a3e48d|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0 10341000x800000000000000060664Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12af2c2|C:\Program Files\Mozilla Firefox\xul.dll+14855cd|C:\Program Files\Mozilla Firefox\xul.dll+2a3e43d|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac|C:\Program Files\Mozilla Firefox\xul.dll+1611d2 10341000x800000000000000060663Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac 10341000x800000000000000060662Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+2a3e130|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4 10341000x800000000000000060661Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+2a3e0a2|C:\Program Files\Mozilla Firefox\xul.dll+2a3d71c|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4|C:\Program Files\Mozilla Firefox\xul.dll+3b652e0|C:\Program Files\Mozilla Firefox\xul.dll+109061 10341000x800000000000000060660Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.187{7CDEDE96-003C-60AE-7C02-00000000C501}41402660C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+121aacf|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+20088|C:\Program Files\Mozilla Firefox\xul.dll+11f5c88|C:\Program Files\Mozilla Firefox\xul.dll+1f4a5|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+1e9ef|C:\Program Files\Mozilla Firefox\xul.dll+11f6a01|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060659Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.171{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060658Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.171{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060657Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.171{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060656Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.171{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060655Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.171{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000060654Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.171{7CDEDE96-003C-60AE-7C02-00000000C501}41405676C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+1845f|C:\Program Files\Mozilla Firefox\firefox.exe+432db|C:\Program Files\Mozilla Firefox\firefox.exe+247e8|C:\Program Files\Mozilla Firefox\xul.dll+cf875a|C:\Program Files\Mozilla Firefox\xul.dll+1211234|C:\Program Files\Mozilla Firefox\xul.dll+120f4b2|C:\Program Files\Mozilla Firefox\xul.dll+121beae|C:\Program Files\Mozilla Firefox\xul.dll+da0e64|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f69a|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000060653Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.175{7CDEDE96-003F-60AE-8002-00000000C501}4544C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4140.13.769177808\272833869" -childID 2 -isForBrowser -prefsHandle 3364 -prefMapHandle 3360 -prefsLen 5327 -prefMapSize 238570 -parentBuildID 20210504152106 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4140 "\\.\pipe\gecko-crash-server-pipe.4140" 3372 tabC:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542LowMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" 17141700x800000000000000060652Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:03.156{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.13.76917780C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000060651Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.156{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060650Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.156{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\sessionCheckpoints.jsonMD5=EA8B62857DFDBD3D0BE7D7E4A954EC9A,SHA256=792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060649Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.156{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060648Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.124{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=083D7D94793F0867689BF23D3C972A5C,SHA256=265C773FED7AEFE6045A999E6A78B0A1FE0A4CB886EFF6A20A9512ACC1D39469,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060647Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.025{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c95118|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+2dfed3b|C:\Program Files\Mozilla Firefox\xul.dll+2e00c4c|C:\Program Files\Mozilla Firefox\xul.dll+2951b0|C:\Program Files\Mozilla Firefox\xul.dll+2e506e0|C:\Program Files\Mozilla Firefox\xul.dll+37f3f9d|C:\Program Files\Mozilla Firefox\xul.dll+37f3b18|C:\Program Files\Mozilla Firefox\xul.dll+1530c5c|C:\Program Files\Mozilla Firefox\xul.dll+15306de|C:\Program Files\Mozilla Firefox\xul.dll+25b04a|C:\Program Files\Mozilla Firefox\xul.dll+291361 10341000x800000000000000060646Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.025{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c950f1|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+2dfed3b|C:\Program Files\Mozilla Firefox\xul.dll+2e00c4c|C:\Program Files\Mozilla Firefox\xul.dll+2951b0|C:\Program Files\Mozilla Firefox\xul.dll+2e506e0|C:\Program Files\Mozilla Firefox\xul.dll+37f3f9d|C:\Program Files\Mozilla Firefox\xul.dll+37f3b18|C:\Program Files\Mozilla Firefox\xul.dll+1530c5c|C:\Program Files\Mozilla Firefox\xul.dll+15306de|C:\Program Files\Mozilla Firefox\xul.dll+25b04a|C:\Program Files\Mozilla Firefox\xul.dll+291361 10341000x800000000000000060645Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.025{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+2c950c6|C:\Program Files\Mozilla Firefox\xul.dll+589c7e|C:\Program Files\Mozilla Firefox\xul.dll+588c1f|C:\Program Files\Mozilla Firefox\xul.dll+588a0a|C:\Program Files\Mozilla Firefox\xul.dll+2ce71a7|C:\Program Files\Mozilla Firefox\xul.dll+58820d|C:\Program Files\Mozilla Firefox\xul.dll+2e0e2ee|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e0e44f|C:\Program Files\Mozilla Firefox\xul.dll+2e1068d|C:\Program Files\Mozilla Firefox\xul.dll+29495d|C:\Program Files\Mozilla Firefox\xul.dll+2dfed3b|C:\Program Files\Mozilla Firefox\xul.dll+2e00c4c|C:\Program Files\Mozilla Firefox\xul.dll+2951b0|C:\Program Files\Mozilla Firefox\xul.dll+2e506e0|C:\Program Files\Mozilla Firefox\xul.dll+37f3f9d|C:\Program Files\Mozilla Firefox\xul.dll+37f3b18|C:\Program Files\Mozilla Firefox\xul.dll+1530c5c|C:\Program Files\Mozilla Firefox\xul.dll+15306de|C:\Program Files\Mozilla Firefox\xul.dll+25b04a|C:\Program Files\Mozilla Firefox\xul.dll+291361 10341000x800000000000000060644Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.009{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060643Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.000{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037926Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:04.183{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=54A35B17D40F022612D456B1A3AF232F,SHA256=04693C0C0EF7F6C8C61B8BC88236D138A59289308013926CF4EE862EBD1C10BF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060911Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.996{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-unwanted-proto-1.vlpsetMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060910Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.981{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-malware-proto.metadataMD5=7BB91D7B40EA0EAC38381BDCA4278423,SHA256=F50B54295E8FC24FC6BD66B93C4F2427D85EEC09382C7BE22ADCB7626FD8724D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060909Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.981{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-malware-proto-1.vlpsetMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060908Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.965{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-phish-proto.metadataMD5=64242577B5786302F7BB4174080EB62B,SHA256=0A46E3E70B27C1D45175CBD660D41ADBF4AF5486C9BB1A48A1E22905536CE0E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060907Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.887{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-phish-proto-1.vlpsetMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060906Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.763{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060905Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.780{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50953-false142.250.184.227fra24s12-in-f3.1e100.net80http 354300x800000000000000060904Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.765{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local64474- 354300x800000000000000060903Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.737{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50952-false142.250.185.234fra16s53-in-f10.1e100.net443https 354300x800000000000000060902Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.737{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58208- 354300x800000000000000060901Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.730{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61964- 354300x800000000000000060900Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.687{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50947-false52.38.88.94ec2-52-38-88-94.us-west-2.compute.amazonaws.com443https 354300x800000000000000060899Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.687{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50948-false52.38.88.94ec2-52-38-88-94.us-west-2.compute.amazonaws.com443https 354300x800000000000000060898Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.633{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60246- 354300x800000000000000060897Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.629{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50382- 354300x800000000000000060896Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.618{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60466- 354300x800000000000000060895Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.557{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50949-false143.204.202.20server-143-204-202-20.fra53.r.cloudfront.net443https 354300x800000000000000060894Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.556{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61183- 354300x800000000000000060893Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.556{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59526- 354300x800000000000000060892Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.551{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63019- 354300x800000000000000060891Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.542{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59558- 354300x800000000000000060890Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.541{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63936- 354300x800000000000000060889Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.538{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58756- 354300x800000000000000060888Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.472{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50946-false143.204.202.6server-143-204-202-6.fra53.r.cloudfront.net443https 354300x800000000000000060887Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.471{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50096- 354300x800000000000000060886Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.471{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51334- 354300x800000000000000060885Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.196{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50945-false34.107.221.8282.221.107.34.bc.googleusercontent.com80http 354300x800000000000000060884Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.154{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57108- 354300x800000000000000060883Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.154{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50944-false13.32.21.3server-13-32-21-3.fra56.r.cloudfront.net443https 354300x800000000000000060882Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.149{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51827- 354300x800000000000000060881Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.148{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50943-false34.107.221.8282.221.107.34.bc.googleusercontent.com80http 354300x800000000000000060880Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.147{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62382- 354300x800000000000000060879Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.146{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62068- 354300x800000000000000060878Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.138{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60325- 23542300x800000000000000060877Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.207{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=270FB5AAC05221EC76C79DDB2B49E025,SHA256=DEA3E978C98C9F383DED275C4407F2985291732295E3A763861C4B153DCC73C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060876Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.140{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000060875Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.856{7CDEDE96-003C-60AE-7C02-00000000C501}4140cs9.wac.phicdn.net9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060874Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.855{7CDEDE96-003C-60AE-7C02-00000000C501}4140cs9.wac.phicdn.net093.184.220.29;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060873Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.569{7CDEDE96-003C-60AE-7C02-00000000C501}4140d228z91au11ukj.cloudfront.net9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060872Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.568{7CDEDE96-003C-60AE-7C02-00000000C501}4140d228z91au11ukj.cloudfront.net0143.204.202.128;143.204.202.50;143.204.202.48;143.204.202.20;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060871Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.555{7CDEDE96-003C-60AE-7C02-00000000C501}4140pipeline-incoming-prod-elb-149169523.us-west-2.elb.amazonaws.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060870Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.554{7CDEDE96-003C-60AE-7C02-00000000C501}4140pipeline-incoming-prod-elb-149169523.us-west-2.elb.amazonaws.com044.235.28.153;34.215.28.152;44.239.250.14;54.149.10.221;34.215.46.102;52.38.70.232;52.27.200.224;52.38.88.94;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060869Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.167{7CDEDE96-003C-60AE-7C02-00000000C501}4140example.org0::ffff:93.184.216.34;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060868Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.167{7CDEDE96-003C-60AE-7C02-00000000C501}4140example.org093.184.216.34;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060867Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.166{7CDEDE96-003C-60AE-7C02-00000000C501}4140d2nxq2uap88usk.cloudfront.net02600:9000:21f3:be00:a:da5e:7900:93a1;2600:9000:21f3:1200:a:da5e:7900:93a1;2600:9000:21f3:1e00:a:da5e:7900:93a1;2600:9000:21f3:5400:a:da5e:7900:93a1;2600:9000:21f3:d800:a:da5e:7900:93a1;2600:9000:21f3:d600:a:da5e:7900:93a1;2600:9000:21f3:9c00:a:da5e:7900:93a1;2600:9000:21f3:8400:a:da5e:7900:93a1;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060866Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.161{7CDEDE96-003C-60AE-7C02-00000000C501}4140d2nxq2uap88usk.cloudfront.net013.32.21.124;13.32.21.125;13.32.21.77;13.32.21.3;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060865Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.161{7CDEDE96-003C-60AE-7C02-00000000C501}4140prod.detectportal.prod.cloudops.mozgcp.net02600:1901:0:38d7::;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060864Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.158{7CDEDE96-003C-60AE-7C02-00000000C501}4140prod.detectportal.prod.cloudops.mozgcp.net034.107.221.82;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000060863Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.152{7CDEDE96-003C-60AE-7C02-00000000C501}4140detectportal.firefox.com0type: 5 detectportal.prod.mozaws.net;type: 5 prod.detectportal.prod.cloudops.mozgcp.net;::ffff:34.107.221.82;C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060862Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1213abc|C:\Program Files\Mozilla Firefox\xul.dll+1321d41|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f69a|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000060861Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.26.207076697C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060860Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.25.152345061C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060859Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.24.16867283C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060858Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.22.188455463C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060857Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.23.38559805C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000060856Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:04.009{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.21.163185724C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000060855Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.008{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060854Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.007{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000037927Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:05.199{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=184C2F0F6691076B7FAC8E1B8E23F102,SHA256=7B211C0F43110C4F5E9392859C60D5F5A4D5A1D4A6F152D8C2DC5ECFC2A390C6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060999Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.959{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\broadcast-listeners.jsonMD5=11217DFBCBE9AB0FF958C01B5790C7DB,SHA256=12CC2CCADFBCCEDE207BE421B86C49E628CD27114943BE215ED7AAC0ED2543C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060998Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.924{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A929565093EFB51C108CA22933BCC540,SHA256=BD04DABAA086CEAAC5C70055F1B05BB8440805F9856CDF592806BD4191AB6E5F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060997Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.877{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060996Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.927{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-57106- 354300x800000000000000060995Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.926{7CDEDE96-F0D1-60AD-1400-00000000C501}1084C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEudptruetrue7f00:1:0:0:98d0:6700:1e2:ffff-57106-true7f00:1:0:0:0:0:0:0-53domain 354300x800000000000000060994Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:03.149{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50956-false10.0.1.12-8000- 10341000x800000000000000060993Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.678{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000060992Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.678{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000060991Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.640{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060990Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.609{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060989Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.552{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060988Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.551{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060987Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.501{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060986Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.501{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060985Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.370{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-tracking-protection-twitter-digest256.vlpsetMD5=B50CF628E0082A7840D84D0CBE1CAD48,SHA256=544DF79BCEF9DC8E082021E342C2A1B12CD0B8BDAF3687E0F23785406EDF33AE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060984Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.354{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-tracking-protection-twitter-digest256.sbstoreMD5=F130C472E963FF3CEED251C65964B927,SHA256=E5D2A5BBE8AA43751EF7F7BC3A817A0963D56272A4C9B6055E60929606186CE2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060983Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.354{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-tracking-protection-linkedin-digest256.vlpsetMD5=5F93E0F827909390D257EBB27C77F392,SHA256=5BCB684F3EE3B2EC2F4945655FBEF281C487399D6BF90451647DB1761715D4C8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060982Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.352{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060981Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.352{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060980Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.351{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060979Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.351{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-tracking-protection-linkedin-digest256.sbstoreMD5=9275B832091D9E3BFE50898A3BE022B5,SHA256=38C52A5435B625083000A054489B95E033F7B352377510DF668CEE749DE5803E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060978Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.350{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-tracking-protection-facebook-digest256.vlpsetMD5=8AC8A05028631170937EDA4CF0E0A35A,SHA256=456AB2C0E4E117D62DC529362EB22C725D410098868442729ADE5E4FF0822E78,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060977Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-tracking-protection-facebook-digest256.sbstoreMD5=7BBA9B83F0F213C5A723209D4C9962CE,SHA256=E1B8E7DEB0F34EEB6BF4D10E47E734A1FE829C365DF360B98646D7E11F2DD4C7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060976Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-track-digest256.vlpsetMD5=16BF2AA546411BA25DC80EA288D47143,SHA256=524EC56C023155C7BE4C84D5AEC4FE2D85DFBAB3C2FA27F82BCD35028D546F83,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060975Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\social-track-digest256.sbstoreMD5=69EE5B232870704AFCC0E8957AA42A0F,SHA256=EC8DF5279022B68C0B542EC1688889374754106DFADBF7CAF8337E3F98865941,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060974Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\mozstd-trackwhite-digest256.vlpsetMD5=1C82A0FCB1A71CF979139F4EA4782CDA,SHA256=678BBCB65B3773ED1DF2350A86067B6A8E93D749730509C5748088FB3AF85561,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060973Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\mozstd-trackwhite-digest256.sbstoreMD5=4229EE011D82D02008C80898F88BB589,SHA256=71E39823CAF19BE44C66DA1056A3DB3B18FE5DB46594A6EBBD41F6267503FAB9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060972Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060971Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\mozplugin-block-digest256.vlpsetMD5=FCC9C2C9B611A3264B68EBE180EB4248,SHA256=6ECD378A537EEFE350B45CFA353741383F407D99D776BF23155A7825DC5DD2BC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060970Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060969Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060968Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060967Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.332{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\mozplugin-block-digest256.sbstoreMD5=519BEB1B01FC355BB388F1F75BE997FD,SHA256=FFE2D3077B81AE6F51B220C1C661B276C823FA67DAD1D64FC5F17249FC54BDC0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060966Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.324{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-unwanted-proto.vlpsetMD5=43DC21B3F24A9AC4F7708DDD9343A3A6,SHA256=C30CB8BA96426FA234A63F355D69F7D25F91729103F00703C99C31FE409C90FA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060965Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.324{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-unwanted-proto.metadataMD5=CA8439E3D80E134345163144F7522A4D,SHA256=A2DA337FCDA07866EA5C8D8AB857B0272C787144ABB87E569BA1312D2FBA96D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060964Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.304{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-phish-proto.vlpsetMD5=DA338FAA8C6D15AEA90E4A349D411CAE,SHA256=94A17620334E4E20E1123A02705D8F5E68B991B08ACE6EDF730EF0923A4D6AC8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060963Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.304{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060962Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.304{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA9758560E2248B66B7DD8102BE8ECBD,SHA256=617B1E2AA80B9F7A78DA2B83FCA3CE14F39068E2F6BFB907B08C078F25EA8526,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060961Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.304{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060960Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.270{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000060959Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.254{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060958Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.254{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-phish-proto.metadataMD5=64242577B5786302F7BB4174080EB62B,SHA256=0A46E3E70B27C1D45175CBD660D41ADBF4AF5486C9BB1A48A1E22905536CE0E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060957Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.254{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-malware-proto.vlpsetMD5=FEE88641553B3D4B01640BC4ED271393,SHA256=398B68196F1F7B9A291DE8B1CA9319E4C87B07F4D94E013876660F7FAB167D22,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060956Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.254{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-malware-proto.metadataMD5=7BB91D7B40EA0EAC38381BDCA4278423,SHA256=F50B54295E8FC24FC6BD66B93C4F2427D85EEC09382C7BE22ADCB7626FD8724D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060955Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.254{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-downloadwhite-proto.vlpsetMD5=EA86E0097B81FDBDEE3F12AC90CA6410,SHA256=6A242B62530E38DDCFD272643F6CC44EDC0208C69DC3022D6CC273F4C7E79AF8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060954Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.254{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-downloadwhite-proto.metadataMD5=34C9FC8C4EE2F9EF3E5ADB863BCAEFEF,SHA256=A2C2674C2C8C82D7AEEB14CA206B4D3FA50BAD43FB641F914A259B1F8A81D782,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060953Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.237{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-badbinurl-proto.vlpsetMD5=6B27149A99E8432457361673301542FA,SHA256=81E6571605E92932385A6B80CA4B7A165FD00C1033933488AEFDAE322AF27839,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060952Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.236{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-badbinurl-proto.metadataMD5=E0647ED9C3300DB84881FFEB4F42C11C,SHA256=E82358BCC80A7AE1BF39C20DA056CF44460A46AD3306D1BE941D3611DA4B4FAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060951Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.220{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google-trackwhite-digest256.vlpsetMD5=E54E5B84194EEE15E64D2A03F1136BB7,SHA256=07707B589BE3DBA3BB0BDAC67760A2B180EA3531E9D7976B73E4C1D8DF9DBB1E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060950Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.204{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google-trackwhite-digest256.sbstoreMD5=FEC9BC354A7EE92C6FEEFE63E6B0FA26,SHA256=258EF8E6994A09FFB54BD0D5AFEC97C13C31F2EEFB7FE90A2A4C487C87817519,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060949Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.204{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\except-flashsubdoc-digest256.vlpsetMD5=0C0D67875BD75A0227C02DD8529BA01A,SHA256=614BE0169EC36E67223EB9645A98DA66DBFDE5DFBB89BB064F428AAEABDD9D97,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060948Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.204{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\except-flashsubdoc-digest256.sbstoreMD5=22698B4CF784DBBAE2D583F00491D43D,SHA256=3849563088AE0677D61702A1310FDE26DE5DDD846D53037222D3EFE012197BF5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060947Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.204{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\except-flashallow-digest256.vlpsetMD5=7194B6BFF691A056852A51E2E06CE8FE,SHA256=CBE2DC6ABFE25BEAD60F4DFAF419FC0F441FF8A8DD4A2FEBF5553BE1CBD90C49,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060946Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\except-flashallow-digest256.sbstoreMD5=DD0458514C9A922B45DA6A8BEBE47320,SHA256=D27D5B27030F4725249377951BEB89E84A90A0E8241F0D5FD80EA59C1606E761,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060945Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\except-flash-digest256.vlpsetMD5=C2994D388F8780C87D35C352D9582985,SHA256=7ED09F7D2BD632F70077A4AE4F2BD2F3FB654B03CD72652F51678B0C7D027F25,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060944Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\except-flash-digest256.sbstoreMD5=D5D6B4D59B4AE4E2DE4B40D0DA083571,SHA256=000E3A78C72A210CA3B5417A3CDD294FBCE2A31661601C9D594C75CF2800571C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060943Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\content-track-digest256.vlpsetMD5=07FF16BA9846838DA27AE094A1B91369,SHA256=DC83AE90504AC11C29876CFC48483976397E899958EE8EDE7F381971A2C2C4B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060942Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\content-track-digest256.sbstoreMD5=1B9A162CEB3C7BE8393CE348F35A4564,SHA256=2D6B6351BD1B8C2047DA1854D0033EE6C5CD9F1BFE38C5E1A2B82C86AFE8A598,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060941Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.172{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\block-flashsubdoc-digest256.vlpsetMD5=40165280FF1345B5241EC2A9D1DA2AF0,SHA256=F80BDD5341D8B1EE946E344E258EF2D35C3C0BB6B13EB7B3E6A77467DFA8B97F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060940Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.172{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\block-flashsubdoc-digest256.sbstoreMD5=B9556D03AFF392142AD5691D2F867310,SHA256=CFD3909B41C1EE3CBCB8B7D2B1378065E7D3B543FFF1F2FB7A4F25C5FF41722C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060939Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.157{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\block-flash-digest256.vlpsetMD5=130B9AC2BEEC5ADA274561105D81AE36,SHA256=7D99FEC08182A5B95D18D1569EDAA2C60C2AAFBD15A56D8882F22F3B395E6460,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060938Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.157{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\block-flash-digest256.sbstoreMD5=9F6B331AA1E070DCFEED473E76CE56C3,SHA256=7DBBEA2DD387EEB85E1F56E02FC9989ACDE570CD43BFEF2C2A827093BA87DA6D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060937Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.141{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\base-fingerprinting-track-digest256.vlpsetMD5=5D2B92240C8C7B21B696B5F4332ECC3D,SHA256=20F25748FF8ED62B5F8364C5B9141ECAB60BBFD35352A4613A75333D35F3D293,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060936Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.132{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\base-fingerprinting-track-digest256.sbstoreMD5=438CA2D8E476411D622FA556E3F6DFC8,SHA256=06CEBA967D57F01F6EC3E8A5677813CA650F21CD69BE83F8238749486A4D9A3E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060935Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.132{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\base-cryptomining-track-digest256.vlpsetMD5=82E921320B62879B070EBE9D8F1F4256,SHA256=A781BFF04964067CB06EA80DA605A4A2837F7256580693C6DBDCA971D8C9BDB0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060934Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.131{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\base-cryptomining-track-digest256.sbstoreMD5=BB9BB51CB484CC5719D210D53CF37762,SHA256=1903A36C25AEB3C61953484ED931ED52AB4A3BD13FCC38046154A6681472D499,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060933Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.129{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\analytics-track-digest256.vlpsetMD5=E5F58C529331DE1A7E3A96699C0AE92E,SHA256=698FD8CCC3F1B3A6D8CE8B2A580C277CAA34FAB0590FA0574AEF0025C0501FA5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000060932Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.125{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805520C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000060931Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.125{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\analytics-track-digest256.sbstoreMD5=F744ED601A4BEF57BC0FB538C0D51EEE,SHA256=8B3FB99021D4F6BD267897D15D3EBA7A3F5BB87125C8DB10F0FE362BB0CF140A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060930Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.123{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\allow-flashallow-digest256.vlpsetMD5=DE0D88480C24350C59E1E9A3583DE0D1,SHA256=01BA9F0B913E04ED10BD7166796483DD4F72005F249D6EE68B12117BE4B5D3C7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060929Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.107{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\allow-flashallow-digest256.sbstoreMD5=DD0458514C9A922B45DA6A8BEBE47320,SHA256=D27D5B27030F4725249377951BEB89E84A90A0E8241F0D5FD80EA59C1606E761,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060928Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.107{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\ads-track-digest256.vlpsetMD5=BF207C6726A4D58C22C96E138046BD45,SHA256=B2C1380591B984CD3406C519DE0A2C2B8B040BFF216F68E44563B670F324C8F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060927Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.092{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\ads-track-digest256.sbstoreMD5=A165346B708E2F7C27647CF04ECD827C,SHA256=14B5D79CA80785F1B4C6993A2A65C123CDF324CA20E1434D6DC3CDE31970A89E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060926Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.061{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-badbinurl-proto.metadataMD5=E0647ED9C3300DB84881FFEB4F42C11C,SHA256=E82358BCC80A7AE1BF39C20DA056CF44460A46AD3306D1BE941D3611DA4B4FAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000060925Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:05.061{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-badbinurl-proto-1.vlpsetMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000060924Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.876{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50951-false44.229.141.128ec2-44-229-141-128.us-west-2.compute.amazonaws.com443https 354300x800000000000000060923Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.867{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50895- 354300x800000000000000060922Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.866{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59569- 354300x800000000000000060921Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.866{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local64519- 354300x800000000000000060920Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.865{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59992- 354300x800000000000000060919Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.865{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63091- 354300x800000000000000060918Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.864{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50950-false52.38.88.94ec2-52-38-88-94.us-west-2.compute.amazonaws.com443https 354300x800000000000000060917Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.843{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50955-false93.184.220.29-80http 354300x800000000000000060916Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.843{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50954-false93.184.220.29-80http 354300x800000000000000060915Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.843{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62363- 354300x800000000000000060914Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.843{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62204- 354300x800000000000000060913Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:02.839{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50118- 23542300x800000000000000060912Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.996{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\safebrowsing-updating\google4\goog-unwanted-proto.metadataMD5=CA8439E3D80E134345163144F7522A4D,SHA256=A2DA337FCDA07866EA5C8D8AB857B0272C787144ABB87E569BA1312D2FBA96D3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037929Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:04.307{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50518-false10.0.1.12-8000- 23542300x800000000000000037928Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:06.214{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB793E1BCD06C9DD61D036DA736AA9E3,SHA256=2C81F9EE29F21C92EC765C7A5541D8026C1D1E13D5E67B1713DE73FB5C6B2A74,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061034Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.396{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local64128- 354300x800000000000000061033Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.396{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63698- 354300x800000000000000061032Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.395{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local64853- 354300x800000000000000061031Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.395{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59152- 354300x800000000000000061030Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.387{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51711- 354300x800000000000000061029Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.379{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local65022- 354300x800000000000000061028Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.378{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57147- 354300x800000000000000061027Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.378{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-49600- 354300x800000000000000061026Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.361{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63403- 354300x800000000000000061025Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.360{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61039- 354300x800000000000000061024Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.360{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58791- 354300x800000000000000061023Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.359{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local49600- 354300x800000000000000061022Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.359{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50525- 354300x800000000000000061021Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.346{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58649- 354300x800000000000000061020Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.346{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58595- 354300x800000000000000061019Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.345{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local49238- 354300x800000000000000061018Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.345{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59509- 354300x800000000000000061017Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.342{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60869- 354300x800000000000000061016Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.342{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local65137- 354300x800000000000000061015Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.342{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63286- 23542300x800000000000000061014Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:06.124{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=00D702D34AC5B82124385E2758D994C3,SHA256=FBA74E73819F81A3196928F35FAF183F0393664915BEF414319F12046E888D79,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061013Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.065{7CDEDE96-F0D1-60AD-1400-00000000C501}1084C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEudpfalsefalse127.0.0.1-57106-false127.0.0.1-53domain 22542200x800000000000000061012Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.372{7CDEDE96-003C-60AE-7C02-00000000C501}4140dyna.wikimedia.org091.198.174.192;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061011Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.372{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.wikipedia.org0type: 5 dyna.wikimedia.org;::ffff:91.198.174.192;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061010Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.372{7CDEDE96-003C-60AE-7C02-00000000C501}4140star-mini.c10r.facebook.com0157.240.20.35;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061009Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.371{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.facebook.com0type: 5 star-mini.c10r.facebook.com;::ffff:157.240.20.35;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061008Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.370{7CDEDE96-003C-60AE-7C02-00000000C501}4140youtube-ui.l.google.com02a00:1450:4001:809::200e;2a00:1450:4001:800::200e;2a00:1450:4001:801::200e;2a00:1450:4001:831::200e;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061007Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.370{7CDEDE96-003C-60AE-7C02-00000000C501}4140djvbdz1obemzo.cloudfront.net9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061006Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.359{7CDEDE96-003C-60AE-7C02-00000000C501}4140e11847.g.akamaiedge.net9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061005Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.357{7CDEDE96-003C-60AE-7C02-00000000C501}4140youtube-ui.l.google.com0142.250.181.238;216.58.212.174;142.250.74.206;142.250.186.174;142.250.184.206;142.250.184.238;172.217.18.110;172.217.23.110;216.58.212.142;142.250.185.78;172.217.16.142;142.250.185.110;142.250.185.142;142.250.185.174;142.250.185.206;142.250.185.238;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061004Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.357{7CDEDE96-003C-60AE-7C02-00000000C501}4140djvbdz1obemzo.cloudfront.net013.32.20.223;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061003Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.357{7CDEDE96-003C-60AE-7C02-00000000C501}4140e11847.g.akamaiedge.net0104.101.101.218;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061002Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.357{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.youtube.com0type: 5 youtube-ui.l.google.com;::ffff:142.250.185.238;::ffff:142.250.181.238;::ffff:216.58.212.174;::ffff:142.250.74.206;::ffff:142.250.186.174;::ffff:142.250.184.206;::ffff:142.250.184.238;::ffff:172.217.18.110;::ffff:172.217.23.110;::ffff:216.58.212.142;::ffff:142.250.185.78;::ffff:172.217.16.142;::ffff:142.250.185.110;::ffff:142.250.185.142;::ffff:142.250.185.174;::ffff:142.250.185.206;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061001Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.357{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.amazon.de0type: 5 tp.abe2c2f23-frontier.amazon.de;type: 5 djvbdz1obemzo.cloudfront.net;::ffff:13.32.20.223;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061000Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.357{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.ebay.de0type: 5 slot11847.ebay.com.edgekey.net;type: 5 e11847.g.akamaiedge.net;::ffff:104.101.101.218;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000061052Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:07.292{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2BE7444FCF696C13807CE57531A87D6,SHA256=2EC40126007C2CE55F40D4E53ECDBDA0C27FCA867D0850A6AC5FA2C6F1443A9F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037930Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:07.230{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B0BB9449136CE8E41305526E6CDB5A4,SHA256=C2A8B01C625C2F8642E07D5ED4EB24556DC7467E7242B1713DB92206740D55B4,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000061051Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.593{7CDEDE96-003C-60AE-7C02-00000000C501}4140farmanager.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061050Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.541{7CDEDE96-003C-60AE-7C02-00000000C501}4140farmanager.com093.174.76.52;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061049Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.538{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.farmanager.com0type: 5 farmanager.com;::ffff:93.174.76.52;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061048Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.421{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.mozilla.org.cdn.cloudflare.net02606:4700::6812:a422;2606:4700::6812:a522;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061047Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.416{7CDEDE96-003C-60AE-7C02-00000000C501}4140e13630.dscb.akamaiedge.net02a02:26f0:1700:1b0::353e;2a02:26f0:1700:195::353e;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061046Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.407{7CDEDE96-003C-60AE-7C02-00000000C501}4140e13630.dscb.akamaiedge.net0104.111.246.93;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061045Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.407{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.mozilla.org.cdn.cloudflare.net0104.18.165.34;104.18.164.34;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061044Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.398{7CDEDE96-003C-60AE-7C02-00000000C501}4140reddit.map.fastly.net9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061043Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.390{7CDEDE96-003C-60AE-7C02-00000000C501}4140reddit.map.fastly.net0151.101.113.140;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061042Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.390{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.reddit.com0type: 5 reddit.map.fastly.net;::ffff:151.101.113.140;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061041Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.390{7CDEDE96-003C-60AE-7C02-00000000C501}4140dyna.wikimedia.org02620:0:862:ed1a::1;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061040Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.373{7CDEDE96-003C-60AE-7C02-00000000C501}4140star-mini.c10r.facebook.com02a03:2880:f11c:8183:face:b00c:0:25de;C:\Program Files\Mozilla Firefox\firefox.exe 354300x800000000000000061039Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.557{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-60030- 354300x800000000000000061038Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.529{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60030- 354300x800000000000000061037Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.527{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62120- 354300x800000000000000061036Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.512{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61973- 354300x800000000000000061035Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.506{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62480- 23542300x800000000000000061058Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:08.522{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CF9F04060625862F98A40F9D643BE133,SHA256=97A54F444E5533549978D29107A6DD5C8A140FCCCABFBD20B3551103F4F74328,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061057Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:08.357{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85AD9BDAE75E4ECF82D9B00B03A0699F,SHA256=85553F1C9EBAEDD202D3C68CE05239305E256FD16BF411683D5E513EFA6F8D09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037931Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:08.246{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16B5D6E9CE6054B1283DDA1AFD9A4B5A,SHA256=D395C8262E94D920A00709A1B1E31C48087470B9B10EE6B12F895EF74D670CD4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061056Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.817{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50958-false93.184.220.29-80http 354300x800000000000000061055Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:04.656{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50957-false54.70.190.152ec2-54-70-190-152.us-west-2.compute.amazonaws.com443https 23542300x800000000000000061054Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:08.076{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\3328MD5=DD8371C2A693252E28A9CAD56567A2D6,SHA256=F28DA673FDA7F7442347DE05386AC3DFE2AF197F9CEAD8EC93C11D7CDBC37420,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061053Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:08.076{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\14011MD5=894D2CD06FD90A4911B36F5954FCB920,SHA256=0E006789C9F9D536F50409F7879541E5DE4080957D065D2B4D17478C517E4C76,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061060Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.806{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\permissions.sqlite-journalMD5=F66DAD15DAEDE4BD72B70D4128111997,SHA256=1F3248950DA357ED9F4109F7984629BED360D238F075F685630A9E816AF535CA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061059Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.376{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3D745A41D507EFA395EAB84926990B75,SHA256=B1D1A3A99CAE39DEF2547079098708B7EABEE134A9AA9ED4E3D721414EAAA867,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037932Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:09.246{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=74B6432E51EBAAE82D2EF5FE30996CE3,SHA256=027D1B59B23CA9A153E264BE738E8BB38F47CDB371B64619548BE59853AD655B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061063Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:10.907{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061062Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:10.875{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061061Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:10.407{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F447B7907B9410FC3639DA6BA90E3F2D,SHA256=CD0093AFD4C0D3739EBADFFDBD67D495B2051D1F6EE89EBE56A29B144C87CD69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037933Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:10.261{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=34009680E3722018AB7A35C47C6973A3,SHA256=EC5491726CDD491C06FE7451CFFE8489122E6BA49D71316CA0B19FB6C067071F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061065Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:11.438{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9303612AC6B0A2E2DED0D5AC78CA395D,SHA256=C3629D2A9D46992FBC24D5E438DD7C0CC80FCA3CCC00D179A520CD1366064921,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037935Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:09.416{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50519-false10.0.1.12-8000- 23542300x800000000000000037934Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:11.277{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8C6CB31AE3417D14C9DACBC2D0906C3,SHA256=82091CF3608AC62D6A67D8D314B933F2432FA0990F6ADFBAC0901BF282BC1435,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061064Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:08.299{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50959-false10.0.1.12-8000- 23542300x800000000000000061071Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:12.474{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C4FA9D08551B04C3945F8577C705EB4,SHA256=DDFDBF0E0D68FED5E78AA083B2D7570C91885E99F9F9386ACD7933FD92C6974C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037936Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:12.293{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C27FF7096ACB30F2BBCDC87592D81AC2,SHA256=E9B21816CC31F145516D13F5372613C3E423674EB0E83216BDA6801CABA7E543,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061070Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.789{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50960-false142.250.185.196fra16s52-in-f4.1e100.net443https 354300x800000000000000061069Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.786{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local49904- 22542200x800000000000000061068Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.801{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.google.com02a00:1450:4001:803::2004;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061067Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.798{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.google.com0142.250.185.196;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061066Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.797{7CDEDE96-003C-60AE-7C02-00000000C501}4140www.google.com0::ffff:142.250.185.196;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000061073Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:13.505{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A602579305CAFF24FA84F48F738BE6C,SHA256=63E7DC30500A53FD650BF8A6295E2E6CC52EDAB8E6BE7515FDB352DB5167D24C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037937Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:13.309{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41F3EAF11B0A06AA87256A8FC86D697D,SHA256=FD8E3F92519272AE82937796471004C86CB9090E07FAF642EB42C7F02D1A185D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061072Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:09.813{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50961-false142.250.184.227fra24s12-in-f3.1e100.net80http 23542300x800000000000000061076Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:14.720{7CDEDE96-F0D1-60AD-1100-00000000C501}388NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=1B7ECD9E7D3A014CF206E7B2EF24A25E,SHA256=AF247173F35E1D3FD1004A351022E04CA26BE37A59B745E63267FB94D024039A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061075Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:14.536{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F43591CF1BB8F3697F9A02F6851CD00,SHA256=0EEFDD9284476D35E23B8623B1C547FAEE7590F63A1ED3AE4C5105AE1062DAF5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037938Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:14.324{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8508E4961D45C630DA5B5630B02C43CE,SHA256=909F866F79D21E9E9DA85F9DAB49B48F3D583C9E429413096AD3D95F460BB28D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061074Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:11.200{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local64541- 23542300x800000000000000061081Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.554{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF11E54E24B17A0AD8B1D040ED8D9FB6,SHA256=D0126B1219E7EB3C002F85D3CC295223C53A45E946DCC59F8F3DA9EFA2D13AF0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037939Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:15.340{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2FAEF604539015D87F7F890E36659D6A,SHA256=36C07CB8C0792A4015630F85D428B49E0D002BB2EBA71993CA0E11EBC9938AEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061080Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.319{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmMD5=C3123D5CFF22B05916E34A7ECA72A6DF,SHA256=948FA279178457A265862756235EC7D56923D6ABBD3E382C21FC0FFDF0D958E2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061079Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.319{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061078Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.319{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061077Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.319{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061125Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.987{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1653105BA530C0F540CC71C5C3A329FB,SHA256=80614F770B78B8CC7263DBABC557057AE545052F1A63E4A9E95AB7942F0FB58C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061124Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.935{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061123Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.856{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061122Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.853{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061121Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.853{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000061120Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.671{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061119Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.671{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061118Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.671{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000037940Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:16.356{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3517B873015C4D6EA41DF5205C9A8C7,SHA256=22EE0BAC2336933BB6C52B7D97D716814DE7CDAB9594F5413DCDBBDC36C75AD7,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061117Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.571{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061116Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.571{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061115Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.571{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061114Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.571{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061113Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.556{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061112Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.556{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061111Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.556{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061110Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.556{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061109Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.556{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061108Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.556{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061107Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.518{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061106Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.518{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061105Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.518{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061104Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.518{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061103Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.518{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061102Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.518{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061101Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.487{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061100Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890 10341000x800000000000000061099Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd 10341000x800000000000000061098Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061097Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000061096Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061095Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 18141800x800000000000000061094Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:16.438{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5944.4.115710754C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061093Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:16.438{7CDEDE96-003F-60AE-8102-00000000C501}5944\chrome.5944.4.115710754C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000061092Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.419{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\protections.sqlite-journalMD5=40D3DEEA517493AE93D04669C6AEFCA2,SHA256=85B1081E2DAF3658ECF3737F9B28B47375579036FEF4E5F36827DCBB1991F26C,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000061091Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:16.387{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5944.3.54620857C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061090Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:16.387{7CDEDE96-003F-60AE-8102-00000000C501}5944\chrome.5944.3.54620857C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061089Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.387{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003F-60AE-8102-00000000C501}5944C:\Program Files\Mozilla Firefox\firefox.exe0x2200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+506f1|C:\Program Files\Mozilla Firefox\xul.dll+2a65add|C:\Program Files\Mozilla Firefox\xul.dll+2a5f4d9|C:\Program Files\Mozilla Firefox\xul.dll+2a5ffd1|C:\Program Files\Mozilla Firefox\xul.dll+2a3c000|C:\Program Files\Mozilla Firefox\xul.dll+37dfb79|C:\Program Files\Mozilla Firefox\xul.dll+1174b11|C:\Program Files\Mozilla Firefox\xul.dll+1177ddc|C:\Program Files\Mozilla Firefox\xul.dll+10e6b01|C:\Program Files\Mozilla Firefox\xul.dll+3d526d|C:\Program Files\Mozilla Firefox\xul.dll+1180607|C:\Program Files\Mozilla Firefox\xul.dll+110c109|C:\Program Files\Mozilla Firefox\xul.dll+1111010|C:\Program Files\Mozilla Firefox\xul.dll+110f32c|C:\Program Files\Mozilla Firefox\xul.dll+110e8a9|C:\Program Files\Mozilla Firefox\xul.dll+110db2e|C:\Program Files\Mozilla Firefox\xul.dll+111dbf8|C:\Program Files\Mozilla Firefox\xul.dll+e4f762|C:\Program Files\Mozilla Firefox\xul.dll+d7c137|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e 23542300x800000000000000061088Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.252{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmMD5=836E0FBC6DCD3D4133536ED0B4627D63,SHA256=4C0FD243331D448558115CA31BFDC0A67E6787C20C0674AFFD0ABB4102FE272D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061087Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.234{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890 10341000x800000000000000061086Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.234{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd 10341000x800000000000000061085Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.234{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061084Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.234{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 23542300x800000000000000061083Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.203{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\formhistory.sqlite-journalMD5=06D351E20629948148DDD9FC79360E35,SHA256=EB12EC9A4B20816D822497334CB3BF959887ACFACABA9B3E1558E08DD3C6E2FB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061082Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:13.329{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50962-false10.0.1.12-8000- 10341000x800000000000000061206Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.935{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061205Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.935{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000061204Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.852{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061203Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.851{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000061202Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.773{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061201Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.773{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 354300x800000000000000061200Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.640{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50965-false142.250.186.99fra24s06-in-f3.1e100.net443https 354300x800000000000000061199Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.640{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61371- 354300x800000000000000061198Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.639{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62795- 23542300x800000000000000061197Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.704{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3BE95CCE85F1A50C3F0906C56D3AB8E8,SHA256=13F03AE9F46F575E353979FC2B9A913B5367AAE4640B43A31E8110BCEC7773B7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037941Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:17.371{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85900C07E21B04C5A0E968506C62D12C,SHA256=FAF60BBBDF6B08C3362FEAFA25F16E223F92EB52A28F9201A84B6F77EBBB8DDA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061196Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.591{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=96A66C952A3181147441D36D45B68F36,SHA256=7FEFF16B62F65CDCBD70F461717002674AB0364F0FADF0EAED2387042024348A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061195Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1213abc|C:\Program Files\Mozilla Firefox\xul.dll+1321d41|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f5cf|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000061194Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.32.108664767C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061193Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.33.74121371C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061192Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.31.42209353C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061191Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.29.102776573C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061190Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.30.94776520C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061189Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.535{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.28.51683739C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061188Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.535{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061187Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.519{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000061186Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.504{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5464.2.94928506C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061185Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.504{7CDEDE96-004D-60AE-8202-00000000C501}5464\chrome.5464.2.94928506C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061184Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.504{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5464.1.109463891C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061183Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.504{7CDEDE96-004D-60AE-8202-00000000C501}5464\chrome.5464.1.109463891C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000061182Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.504{7CDEDE96-004D-60AE-8202-00000000C501}5464\chrome.5464.0.179394954C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061181Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.504{7CDEDE96-004D-60AE-8202-00000000C501}5464\chrome.5464.0.179394954C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061180Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.504{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061179Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.504{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061178Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.473{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+12e04b9|C:\Program Files\Mozilla Firefox\xul.dll+2a4a554|C:\Program Files\Mozilla Firefox\xul.dll+12bbafb|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+d9aecc|C:\Program Files\Mozilla Firefox\xul.dll+4029e|C:\Program Files\Mozilla Firefox\xul.dll+1224a8e|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000061177Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.473{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-3C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061176Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.473{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-3C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061175Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.457{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061174Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.457{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000061173Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.457{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.27.170563505C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061172Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.456{7CDEDE96-003C-60AE-7C02-00000000C501}41405544C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+2aef3b|C:\Program Files\Mozilla Firefox\xul.dll+3aa266d|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000061171Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:01:17.456{7CDEDE96-003C-60AE-7C02-00000000C501}4140\gecko-crash-server-pipe.4140C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061170Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.33.74121371C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000061169Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.32.108664767C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061168Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306841|C:\Program Files\Mozilla Firefox\xul.dll+187cee1|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 17141700x800000000000000061167Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.31.42209353C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061166Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306741|C:\Program Files\Mozilla Firefox\xul.dll+187ccfe|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 17141700x800000000000000061165Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.30.94776520C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061164Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306641|C:\Program Files\Mozilla Firefox\xul.dll+187cb44|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 17141700x800000000000000061163Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.29.102776573C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061162Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+3f93ec|C:\Program Files\Mozilla Firefox\xul.dll+3f933c|C:\Program Files\Mozilla Firefox\xul.dll+12ae2c8|C:\Program Files\Mozilla Firefox\xul.dll+1306541|C:\Program Files\Mozilla Firefox\xul.dll+187c985|C:\Program Files\Mozilla Firefox\xul.dll+2a3e5b8|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 17141700x800000000000000061161Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.28.51683739C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061160Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x2200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+506f1|C:\Program Files\Mozilla Firefox\xul.dll+2a65add|C:\Program Files\Mozilla Firefox\xul.dll+2a5f4d9|C:\Program Files\Mozilla Firefox\xul.dll+2a3e48d|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061159Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12af2c2|C:\Program Files\Mozilla Firefox\xul.dll+14855cd|C:\Program Files\Mozilla Firefox\xul.dll+2a3e43d|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8 10341000x800000000000000061158Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061157Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061156Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061155Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061154Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061153Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061152Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061151Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061150Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061149Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061148Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061147Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061146Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12dd88d|C:\Program Files\Mozilla Firefox\xul.dll+12b136a|C:\Program Files\Mozilla Firefox\xul.dll+12b1224|C:\Program Files\Mozilla Firefox\xul.dll+e0e729|C:\Program Files\Mozilla Firefox\xul.dll+2a3e194|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594 10341000x800000000000000061145Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12b1408|C:\Program Files\Mozilla Firefox\xul.dll+2a63652|C:\Program Files\Mozilla Firefox\xul.dll+2a3e130|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000061144Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+2a3e0a2|C:\Program Files\Mozilla Firefox\xul.dll+2a5bfd4|C:\Program Files\Mozilla Firefox\xul.dll+2a5beed|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+d9b1aa|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061143Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-003C-60AE-7C02-00000000C501}41402660C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+121aacf|C:\Program Files\Mozilla Firefox\xul.dll+cf7244|C:\Program Files\Mozilla Firefox\xul.dll+20088|C:\Program Files\Mozilla Firefox\xul.dll+11f5c88|C:\Program Files\Mozilla Firefox\xul.dll+1f4a5|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+1e9ef|C:\Program Files\Mozilla Firefox\xul.dll+11f6a01|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061142Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061141Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.404{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061140Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.388{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061139Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.388{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061138Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.388{7CDEDE96-F8F0-60AD-7E01-00000000C501}13363908C:\Windows\system32\csrss.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061137Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.388{7CDEDE96-003C-60AE-7C02-00000000C501}41405676C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+1845f|C:\Program Files\Mozilla Firefox\firefox.exe+432db|C:\Program Files\Mozilla Firefox\firefox.exe+247e8|C:\Program Files\Mozilla Firefox\xul.dll+cf875a|C:\Program Files\Mozilla Firefox\xul.dll+1211234|C:\Program Files\Mozilla Firefox\xul.dll+120f4b2|C:\Program Files\Mozilla Firefox\xul.dll+121beae|C:\Program Files\Mozilla Firefox\xul.dll+da0e64|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f69a|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061136Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.402{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe88.0.1FirefoxFirefoxMozilla Corporationfirefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="4140.27.1705635051\1598304384" -childID 4 -isForBrowser -prefsHandle 4412 -prefMapHandle 4408 -prefsLen 8316 -prefMapSize 238570 -parentBuildID 20210504152106 -appdir "C:\Program Files\Mozilla Firefox\browser" - 4140 "\\.\pipe\gecko-crash-server-pipe.4140" 3632 tabC:\Program Files\Mozilla Firefox\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542LowMD5=F7A3347AC587E97C57CFAC49A17BD309,SHA256=6406A0632375EDC8C2EFA84E32EE6771AFFC4E34A45CB6CD7E88E0CA899C74AD,IMPHASH=C483AB042998E5D3F9AC1D5A7C7ABDB2{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" 17141700x800000000000000061135Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:01:17.388{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.27.170563505C:\Program Files\Mozilla Firefox\firefox.exe 354300x800000000000000061134Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.342{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50964-false142.250.184.227fra24s12-in-f3.1e100.net80http 354300x800000000000000061133Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.319{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local49744- 354300x800000000000000061132Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.318{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local49429- 354300x800000000000000061131Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.318{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50110- 354300x800000000000000061130Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.318{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62727- 354300x800000000000000061129Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.316{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51748- 354300x800000000000000061128Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.314{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50963-false142.250.185.196fra16s52-in-f4.1e100.net443https 10341000x800000000000000061127Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.056{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061126Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.053{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000061249Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.929{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061248Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.916{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061247Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.915{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061246Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.878{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061245Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.865{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061244Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.863{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061243Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.821{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9BC3B4FCB91B426A629C58E6362EA3F8,SHA256=CAFBF924A638E674E7FEBD25B1F13BE5105C922E8414A90CDD38E907688003F7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061242Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.806{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50977-false142.250.186.98fra24s06-in-f2.1e100.net443https 354300x800000000000000061241Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.805{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60230- 354300x800000000000000061240Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.804{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62596- 354300x800000000000000061239Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.763{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50976-false142.250.185.130fra16s50-in-f2.1e100.net443https 354300x800000000000000061238Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.763{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local49533- 354300x800000000000000061237Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.760{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57529- 354300x800000000000000061236Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.695{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50975-false142.250.185.234fra16s53-in-f10.1e100.net443https 23542300x800000000000000037943Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:18.387{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C0C870509D5D13BDC938496BB04C2AD7,SHA256=7BD469C8C68832F7C61EC17B23087A08640AEB40F3984CEF2E0C848730AED9D9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061235Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.615{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50974-false172.217.18.98zrh04s05-in-f98.1e100.net443https 354300x800000000000000061234Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.614{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62501- 354300x800000000000000061233Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.613{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51724- 354300x800000000000000061232Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.605{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58517- 354300x800000000000000061231Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.580{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50972-false172.217.23.110mil04s23-in-f110.1e100.net443https 354300x800000000000000061230Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.580{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50973-false172.217.23.110mil04s23-in-f110.1e100.net443https 354300x800000000000000061229Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.568{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50970-false172.217.23.110mil04s23-in-f110.1e100.net443https 354300x800000000000000061228Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.567{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50971-false172.217.23.110mil04s23-in-f110.1e100.net443https 354300x800000000000000061227Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.527{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50969-false142.250.74.206fra24s02-in-f14.1e100.net443https 354300x800000000000000061226Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.514{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58922- 354300x800000000000000061225Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.499{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59081- 354300x800000000000000061224Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.405{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50968-false142.250.184.227fra24s12-in-f3.1e100.net443https 354300x800000000000000061223Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.403{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50967-false142.250.184.227fra24s12-in-f3.1e100.net443https 23542300x800000000000000061222Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.403{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6D113DD82E9CE419859774CEE5B39DA8,SHA256=985DCE186E158C9BF1937A038A608F7C89E11140AE020DC6DEE5829DEF54BEE0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061221Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.403{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D1D08ABE396EE66D82CC37EE6E7DA623,SHA256=93EFDD37097249CAE8695C5A4674F3FD3F49173B322B1A3C24132D115F93161C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061220Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.978{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51240- 354300x800000000000000061219Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.977{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50966-false142.250.186.99fra24s06-in-f3.1e100.net443https 22542200x800000000000000061218Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.773{7CDEDE96-003C-60AE-7C02-00000000C501}4140adservice.google.de0type: 5 pagead46.l.doubleclick.net;::ffff:142.250.185.130;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061217Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.539{7CDEDE96-003C-60AE-7C02-00000000C501}4140plus.l.google.com02a00:1450:4001:80e::200e;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061216Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.526{7CDEDE96-003C-60AE-7C02-00000000C501}4140plus.l.google.com0142.250.74.206;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061215Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:16.525{7CDEDE96-003C-60AE-7C02-00000000C501}4140apis.google.com0type: 5 plus.l.google.com;::ffff:142.250.74.206;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061214Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.995{7CDEDE96-003C-60AE-7C02-00000000C501}4140id.google.com02a00:1450:4007:817::2003;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061213Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.989{7CDEDE96-003C-60AE-7C02-00000000C501}4140id.google.com0142.250.186.99;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061212Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.987{7CDEDE96-003C-60AE-7C02-00000000C501}4140id.google.com0::ffff:142.250.186.99;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061211Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.653{7CDEDE96-003C-60AE-7C02-00000000C501}4140gstaticadssl.l.google.com02a00:1450:4001:830::2003;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061210Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:15.651{7CDEDE96-003C-60AE-7C02-00000000C501}4140gstaticadssl.l.google.com0142.250.186.99;C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061209Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.119{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890 10341000x800000000000000061208Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.119{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd 23542300x800000000000000061207Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.019{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\permissions.sqlite-journalMD5=9F05EA4C1D0D5675788221F39487E374,SHA256=348E86959D10115DD5C2E9DBFB42F2C8074D3904E5D4262FEC38F940430198FA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037942Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:15.276{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50520-false10.0.1.12-8000- 23542300x800000000000000061289Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.840{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F19D61839B33044D64C58C142AEB14FA,SHA256=24CEC081925FC75185917812CCD8E2E3943DEF3EC0DEAF6DF5D04FAF873D2FB0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037944Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:19.403{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=766089A38A1C2CA6D0FBA05DFCD03315,SHA256=B5E484B9AF9B76F751CACAF62A74722A37E199EE9B2D45F721A6A051775B98EB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061288Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.751{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50990-false185.199.108.133cdn-185-199-108-133.github.com443https 354300x800000000000000061287Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.751{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50991-false185.199.108.133cdn-185-199-108-133.github.com443https 354300x800000000000000061286Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.751{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50992-false185.199.108.133cdn-185-199-108-133.github.com443https 354300x800000000000000061285Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.749{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50987-false185.199.108.133cdn-185-199-108-133.github.com443https 354300x800000000000000061284Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.749{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50989-false185.199.108.133cdn-185-199-108-133.github.com443https 354300x800000000000000061283Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.749{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50986-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061282Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.749{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50988-false185.199.108.133cdn-185-199-108-133.github.com443https 354300x800000000000000061281Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.734{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50985-false142.250.185.234fra16s53-in-f10.1e100.net443https 354300x800000000000000061280Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.682{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50982-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061279Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.677{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51907- 354300x800000000000000061278Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.677{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61551- 354300x800000000000000061277Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.675{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50983-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061276Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.675{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50981-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061275Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.675{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50979-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061274Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.675{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50984-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061273Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.674{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50980-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061272Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.672{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57763- 354300x800000000000000061271Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.671{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59834- 354300x800000000000000061270Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.667{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59269- 10341000x800000000000000061269Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.306{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061268Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.305{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000061267Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.274{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061266Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.274{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 354300x800000000000000061265Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.314{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59399- 354300x800000000000000061264Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.313{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local64314- 354300x800000000000000061263Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.313{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50334- 354300x800000000000000061262Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.236{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63489- 354300x800000000000000061261Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.236{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50978-false140.82.121.4lb-140-82-121-4-fra.github.com443https 354300x800000000000000061260Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.236{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59112- 354300x800000000000000061259Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.233{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57747- 10341000x800000000000000061258Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.178{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061257Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.177{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 22542200x800000000000000061256Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.688{7CDEDE96-003C-60AE-7C02-00000000C501}4140avatars.githubusercontent.com0::ffff:185.199.108.133;::ffff:185.199.109.133;::ffff:185.199.110.133;::ffff:185.199.111.133;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061255Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.683{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.githubassets.com0185.199.108.154;185.199.109.154;185.199.110.154;185.199.111.154;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061254Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.681{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.githubassets.com0::ffff:185.199.111.154;::ffff:185.199.108.154;::ffff:185.199.109.154;::ffff:185.199.110.154;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061253Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.250{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061252Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.248{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.com0140.82.121.4;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061251Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.246{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.com0::ffff:140.82.121.4;C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000061250Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.116{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061305Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:20.855{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EE5B466D9AFF4CCA38CC6329ECB38EC,SHA256=B27E1D550D62DC0803098351BDCE7AFB389D5645D6BF4DD0C77CB6B74676F95D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037945Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:20.418{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ECB706ABFABE1936C57CDF8668695993,SHA256=C74E31DAC39AFCA8B00A37B80215337D68F016431048715F54F1ECE9966B4085,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061304Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:20.732{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000061303Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.314{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local65321- 354300x800000000000000061302Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.278{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50993-false52.2.180.220ec2-52-2-180-220.compute-1.amazonaws.com443https 354300x800000000000000061301Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.246{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50994-false140.82.121.5lb-140-82-121-5-fra.github.com443https 354300x800000000000000061300Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.245{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59606- 354300x800000000000000061299Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.242{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58711- 354300x800000000000000061298Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.189{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50356- 22542200x800000000000000061297Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.257{7CDEDE96-003C-60AE-7C02-00000000C501}4140api.github.com0140.82.121.5;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061296Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.255{7CDEDE96-003C-60AE-7C02-00000000C501}4140api.github.com0::ffff:140.82.121.5;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061295Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.203{7CDEDE96-003C-60AE-7C02-00000000C501}4140analytics-collector-28944298.us-east-1.elb.amazonaws.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061294Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.200{7CDEDE96-003C-60AE-7C02-00000000C501}4140analytics-collector-28944298.us-east-1.elb.amazonaws.com03.223.228.231;54.167.199.174;52.54.72.115;52.2.180.220;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061293Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.199{7CDEDE96-003C-60AE-7C02-00000000C501}4140collector.githubapp.com0type: 5 analytics-collector-28944298.us-east-1.elb.amazonaws.com;::ffff:52.2.180.220;::ffff:3.223.228.231;::ffff:54.167.199.174;::ffff:52.54.72.115;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061292Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.697{7CDEDE96-003C-60AE-7C02-00000000C501}4140avatars.githubusercontent.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061291Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.693{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.githubassets.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061290Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:17.689{7CDEDE96-003C-60AE-7C02-00000000C501}4140avatars.githubusercontent.com0185.199.109.133;185.199.110.133;185.199.111.133;185.199.108.133;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000061311Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:21.863{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=109F0D30520F7A31E02AD0053168D9C0,SHA256=A2643E264AA5837D346ED0E02D029BC219C5DB1BC1DE49A1E44A072F51C9D969,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037946Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:21.434{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=78E946A171E1B3377EDD1859DF0B55A7,SHA256=7D31F8C66F3964DDFD6B9622AAE97E4E63C40F5271130D7158C7999F83B78665,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061310Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.322{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60006- 23542300x800000000000000061309Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:21.617{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\permissions.sqlite-journalMD5=4315AC506EF4640490347746A4BCCD9E,SHA256=490BDAFDF30C6710813CEAAC6CDDDE3BB8A97E9573F9E4F58EDB5BD4D52D8A1C,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000061308Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:18.258{7CDEDE96-003C-60AE-7C02-00000000C501}4140api.github.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000061307Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:21.189{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\5914MD5=C96CDFD4C28F2B9496F416F952D6CC7A,SHA256=D400503BB0DA81C1DFA8E2C20A8CCDDC8DF78E2534E56436D4AA2E42C76AD8BE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061306Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:21.188{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\14589MD5=4122EC7DBEF1C7FF8ED0F2C943C7139A,SHA256=83D5D0773C3CD373C02EF9C13F96A6EC8CAB933E7744BD12B0D30F51FB5537AC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061312Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:22.865{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=209BF81BA39C94BB7A39F7E214A2AE6B,SHA256=4CECD84B0FDB731A545E9697D0C6F652736DD8A6A094C359D95CDEE312BDA2F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037947Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:22.450{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8FA00F42781775BADF3800619CDFA670,SHA256=F90CCFE89950F5C15713CD9B462C4FA0BDBD67F9B55B2195C2D3937B4E3E45E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061315Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:23.878{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=95A55CD2E0A5CEED42762424074B2E45,SHA256=5B917341231C5AC37A424B3710B88702A07ADFA7A61D7A40B5D1D8C5485FBFED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037949Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:23.453{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3A72473F15DADFAB212999E0C5EED478,SHA256=C9DDA93340D2EC088CBF7F9802C4E838FFE6D48627617A583C06BE90AABC95E4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061314Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.534{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50059- 354300x800000000000000061313Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:19.146{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50995-false10.0.1.12-8000- 354300x800000000000000037948Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:20.401{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50521-false10.0.1.12-8000- 23542300x800000000000000061316Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:24.879{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C62C1B897783B7DF4EC97E2BE517FAC,SHA256=127AAF075A10CA5328790C1BE67962620D76E337081349B7FB8E582E0A9CA4A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037951Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:24.859{266C2353-F0DB-60AD-1000-00000000C601}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=DC8EC17862FE623F4FB58CBF11436298,SHA256=E01901F474E4218435A72DC023A6653FA91296DF6D8419FC83DA7F7AD6CC1455,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037950Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:24.468{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FEE65D8DC350FF157A66CE0485428F4B,SHA256=82640DB4C88D95E0B95CBD5B7BFA713CA021B106F5659324020231D893E9261C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061317Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:25.882{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F67E8305A6F10DA59D0F2EA4DB6A65A,SHA256=BAB3398CAD8226CEBC493627A24954B27EE6FA247AD880CF458F05C9B380F653,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037952Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:25.484{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03E706425B50B1802A7203FFBFEB0E85,SHA256=FF700F151EB900692ECB32AAE0124DB7CFFCC777315D493D772E3820A66F9C5D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061318Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:26.912{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC991E83AE2E2FA39545913B232AA116,SHA256=C77B14314ED3E651DAF33C8AD704C1E3F848E9C7B7428CD1B515C43B5AFE87D0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037953Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:26.500{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB0229918CE4A16C202E7D4445110F75,SHA256=29EE99F7A3DD195959F51E0BA83EABE0429EBC28C03BD9A0CE96E41323D60BA3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037954Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:27.515{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C4706E495C81F0C63AADBC69DF597F4,SHA256=619BAC6DE7A71B0022F262EFEB1AA5231E9CA0DF9FAFB33CD1BE4F910F3FA56C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061320Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:27.912{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C852EF9A84A9ACF4F89606CED304C324,SHA256=1C0B41A4B03DE0070D25AAC3CDF0BC15C1154D0CCDDFF1E47F41AEC8481C1970,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061319Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:24.240{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local50996-false10.0.1.12-8000- 23542300x800000000000000061322Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.927{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=603593762057DD44F5F24207F9C093CF,SHA256=2FF7CED0381E7015DF0E9AE1743E8A6EF45EB1DBEEFF35AFBB7F0EA39B0EDC98,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037956Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:28.531{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E94FE5B2718947B65526FD2A1E776AAA,SHA256=9BFC32EE7C363C1BC913DD7E0CB6968E5E95D103E2D7484F5C6496D5FEDDE8BC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037955Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:26.169{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50522-false10.0.1.12-8000- 23542300x800000000000000061321Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.528{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=09940042BB93987CE80552B27C3336BD,SHA256=9F5105DDCA78B0311728FE9E1E2E2BF675A12EB1DD8F81B44EC353064F3D392D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061325Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:29.928{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C653A84E4902AEBCA50409F2B19D637,SHA256=FD188EC11E6ECC48A5F0A559D382285B5CED762D8581B3735B70090AB497F401,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037957Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:29.547{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A54B738C3FFA0AD69B20E1266D829FF,SHA256=734BDC0A3E58C81C675FFE4BAFDBD0D30CB16020123AC38A337028D1146168A7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061324Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:29.611{7CDEDE96-F0E1-60AD-3000-00000000C501}2240NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061323Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:29.243{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\indexMD5=1738BFE22E0F1D173684C34A29EEAD7F,SHA256=F0B5B186556A144E2DF7B75FB8943DB1046D19F6E0652FF78D82D4D3ACA498BF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061338Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.720{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51000-false10.0.1.12-8089- 354300x800000000000000061337Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.593{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51164- 354300x800000000000000061336Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.591{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50999-false13.32.21.3server-13-32-21-3.fra56.r.cloudfront.net443https 354300x800000000000000061335Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.407{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50998-false34.98.75.3636.75.98.34.bc.googleusercontent.com443https 354300x800000000000000061334Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.406{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57177- 354300x800000000000000061333Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.405{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local61818- 354300x800000000000000061332Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.399{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51959- 354300x800000000000000061331Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.384{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local50997-false143.204.202.54server-143-204-202-54.fra53.r.cloudfront.net443https 354300x800000000000000061330Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.383{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57911- 354300x800000000000000061329Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.383{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60044- 354300x800000000000000061328Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.369{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63423- 23542300x800000000000000061327Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:30.929{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=322BD8AED7D48C42B96479BF401DF054,SHA256=77C49AC65C01D47A1100A5C812D3BEB147E532473807363FAB4E57F3C3F65BD8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037958Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:30.563{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F7B2A82CFFACFCEBE80BFCA7275D84F,SHA256=ACA2CB1E18AC77A331A7E3C776638761DA2D5E3F78A823FD5F0EC8D300C2DD87,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061326Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:30.643{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061341Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:31.945{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1451C9D026E299440E52D92298E10583,SHA256=5F77E926A3A68CD27ACE2DD09BBE5DD6EB9973A3A70BEDE21C452EBDDBE7FE44,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000037959Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:31.565{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA39420721AB128CFCD4CED3F2DE97DF,SHA256=6D700B2A3B466F59E46FCAAB3E274016ED63E0384412A57A8C72AF22D0CE71AE,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000061340Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.419{7CDEDE96-003C-60AE-7C02-00000000C501}4140prod-classifyclient.normandy.prod.cloudops.mozgcp.net9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061339Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.417{7CDEDE96-003C-60AE-7C02-00000000C501}4140prod-classifyclient.normandy.prod.cloudops.mozgcp.net034.98.75.36;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000037960Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:32.578{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE3B5B4B36C8591F73296D29DA708F02,SHA256=B512CCC1D59D22BBE91B3CB5D21CC095AC86C1D5FC6F977899F70052657281A9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061345Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:32.965{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FFA904D5A1089D2B851FC9C83BE824AF,SHA256=A1DECD715D00B6EB88D686C50879B5D1F3B1283C0980A30A6E990E60849D0D64,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061344Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:32.928{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000061343Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:28.605{7CDEDE96-003C-60AE-7C02-00000000C501}4140d2nxq2uap88usk.cloudfront.net013.32.21.125;13.32.21.3;13.32.21.77;13.32.21.124;C:\Program Files\Mozilla Firefox\firefox.exe 354300x800000000000000061342Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:29.305{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51001-false10.0.1.12-8000- 23542300x800000000000000037961Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:33.784{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=61C5DC8BFEE71520ABAF45D24DF32C46,SHA256=D70B74CE074F4B4DDF057C190DA041A6D9C73A225ECB282B2353A83CD0434FE8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061348Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:33.981{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=77228BEC58E57EF5D54A2C64086811D3,SHA256=F2B086F488F347C09109FDF1B9B74819D0D13DF4C0D7BB880C23BF6F2ED8B6AB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061347Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:33.744{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061346Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:30.054{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local50474- 23542300x800000000000000037963Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:34.909{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2BD5025C7275D52CFE79B523DA172623,SHA256=A10B116F8D239C278BEB6BC3D1EB3810D94D6CF09861EC474AF61699EB1546AF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061350Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:34.991{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A85B23AC12C52A7A066F2B7760F8BAFF,SHA256=AC12B6F148C2974B26CF480A505AA3283D23547036E41EFD3F059B0E4CA773F3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000037962Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:31.262{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50523-false10.0.1.12-8000- 23542300x800000000000000061349Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:34.250{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\21582MD5=CB2F3162EDCD421D11B956845517AAC3,SHA256=E15FBB9DDDE6D79381877DAE57F558D321740D96FB3FF8DE00EC16B51D671764,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037991Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0060-60AE-4D02-00000000C601}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037990Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037989Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037988Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037987Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037986Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037985Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037984Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037983Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037982Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037981Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0060-60AE-4D02-00000000C601}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000037980Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0060-60AE-4D02-00000000C601}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037979Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.909{266C2353-0060-60AE-4D02-00000000C601}3296C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000037978Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.424{266C2353-0060-60AE-4C02-00000000C601}34441312C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037977Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0060-60AE-4C02-00000000C601}3444C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037976Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037975Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037974Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037973Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037972Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037971Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037970Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037969Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037968Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037967Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0060-60AE-4C02-00000000C601}3444C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000037966Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.237{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0060-60AE-4C02-00000000C601}3444C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037965Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.238{266C2353-0060-60AE-4C02-00000000C601}3444C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000037964Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:36.127{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8DFBD715BB48134555A69CCF54EF2505,SHA256=7F8B92027E423492D0FF2D6EF8913CFC589D87E2D9DA55CFF16632B0DE72A75A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061351Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:36.006{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF77A6E83C4EF82E9EA364DADD62B5BB,SHA256=89F1355E0537EAB6B2E66B70235120A19C71AF42687C46C6B8202F1379BD4646,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038007Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7FFA288F5FE9B5A4931A107503DC37EB,SHA256=7F90263FD9CB4E0F441A98789EB1ACCDBA55CF143C362581091DE0E5BD6E251A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038006Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0061-60AE-4E02-00000000C601}2904C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038005Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038004Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038003Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038002Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038001Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038000Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037999Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037998Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037997Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000037996Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0061-60AE-4E02-00000000C601}2904C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 23542300x800000000000000037995Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DBCFD5B51F65D41A0F8B1FCA697F05E,SHA256=979D67FC918589E00697C219EB4FEF121D406B1F53AAAB10404F379030CDD362,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000037994Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0061-60AE-4E02-00000000C601}2904C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000037993Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.567{266C2353-0061-60AE-4E02-00000000C601}2904C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000037992Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.565{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=001BBBD5B9687CD0F80674ED315F6FD1,SHA256=6786F3E74AB5ADD7F79B0147C3B4F6952C02524882C7313DF3789CA64747D173,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061353Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:37.221{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\xulstore.jsonMD5=2419C06E134CF282D06821F4FE1AE25E,SHA256=80483A7B32152222DA909CCDEB0D81831B954D4483DD37161DEEA6F2EA0D163A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061352Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:37.021{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B21D9FAD043A463218FD35968D9BB3BB,SHA256=4C619EF1948E94C6956674A1E79656AA7C3A44BD9924B1804033BBDCFD807640,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038009Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:38.659{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7FFA288F5FE9B5A4931A107503DC37EB,SHA256=7F90263FD9CB4E0F441A98789EB1ACCDBA55CF143C362581091DE0E5BD6E251A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038008Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:38.643{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A2D8E1255B9697071E9FE48CD9F9422D,SHA256=34D937BB090A504AFAC384E0E06BBE40112E97C55A4A7A98CC6738721C33F3B4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061355Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:35.177{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51002-false10.0.1.12-8000- 23542300x800000000000000061354Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:38.036{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4231F33A3C7CB81AE722C977CCF1265F,SHA256=A38B1E1DCDD29DE39A5D7E4954A84A49B5F6E7A17EDBD727B759F3DE05E22D3E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038024Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0063-60AE-4F02-00000000C601}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038023Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038022Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038021Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038020Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038019Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038018Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038017Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038016Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038015Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038014Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0063-60AE-4F02-00000000C601}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038013Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.846{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0063-60AE-4F02-00000000C601}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038012Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.847{266C2353-0063-60AE-4F02-00000000C601}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038011Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:39.659{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2FD8D11264D026B53423005209F61072,SHA256=A04826FF2EC3461DED2719046A4431B3CBC9B0EE695A473FFA0D50E218EFCFEC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061356Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:39.088{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B669990CD17F681C4AC76EFED2C40A21,SHA256=0579989098B6C1B99EB8DDC8B05A28AEBC657A859D1BE6B600EAE7624A94C573,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038010Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:37.249{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50524-false10.0.1.12-8000- 23542300x800000000000000038041Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.987{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=29634A6447266195535D00BA42146EEA,SHA256=E834633E219D656C04B10540B810B42C59FA249DFFF03625E7D79E4D7FE3873A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038040Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.987{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A0487A8E1424A105F5ED90D7D74C9ED6,SHA256=B2F021830874E8DC00090F5B7C4F45B5D17796A6AE771BB401F6AF6B42EB51FA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038039Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.722{266C2353-0064-60AE-5002-00000000C601}31042808C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061357Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:40.089{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=024BFCAE382834DD925A9D57602F5D78,SHA256=8CDF27F3BD704669596CEC921B94BC53A4B634C5C47EEF3DB3C256A419D85F05,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038038Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0064-60AE-5002-00000000C601}3104C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038037Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038036Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038035Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038034Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038033Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038032Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038031Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038030Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038029Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038028Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0064-60AE-5002-00000000C601}3104C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038027Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.518{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0064-60AE-5002-00000000C601}3104C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038026Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.519{266C2353-0064-60AE-5002-00000000C601}3104C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038025Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:40.018{266C2353-0063-60AE-4F02-00000000C601}36402868C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038056Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.956{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37187A335BF914BC4BE124D83AF498FF,SHA256=0B3A3FD377551A9FA08165161828B70449830759F8AA0450C2E224272B62426B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061367Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.489{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061366Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.372{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0065-60AE-8302-00000000C501}4572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061365Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.370{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061364Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.370{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061363Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.370{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061362Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.370{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061361Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.369{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-0065-60AE-8302-00000000C501}4572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061360Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.369{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0065-60AE-8302-00000000C501}4572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061359Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.368{7CDEDE96-0065-60AE-8302-00000000C501}4572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061358Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:41.103{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C78F2C1E814F81615405DB3E4FCF8D4A,SHA256=DBB371E5721AA97AA20DF2209E76ED6C8BB8BDF01E24B81F9F3A2E193EBEE65B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038055Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.331{266C2353-0065-60AE-5102-00000000C601}27083240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038054Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0065-60AE-5102-00000000C601}2708C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038053Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038052Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038051Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038050Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038049Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038048Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038047Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038046Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038045Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038044Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0065-60AE-5102-00000000C601}2708C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038043Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.190{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0065-60AE-5102-00000000C601}2708C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038042Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:41.191{266C2353-0065-60AE-5102-00000000C601}2708C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061381Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.389{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=710035696F1ADB766F22EE7045BFC09B,SHA256=776C543FF41AC15B4D8E81CB6170A24F80BF34A636D64094C0C54AF39CA7A5A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061380Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.389{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6D113DD82E9CE419859774CEE5B39DA8,SHA256=985DCE186E158C9BF1937A038A608F7C89E11140AE020DC6DEE5829DEF54BEE0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061379Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.220{7CDEDE96-0066-60AE-8402-00000000C501}17166100C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061378Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.120{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=648482A4605A7601DF908F8BB95BAE78,SHA256=81D1D6C32DA192601A8F0A1D5BE1B36DE7EBB4F60D2ABD12D3AD8473E30D87EE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061377Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.120{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061376Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.120{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038057Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:42.222{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F81C5C141B77EFA2A23AE842436EDEA3,SHA256=373DC8015F29766642F672E8F9BE93FB93FC502029570EF91B6FF3492F08241F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061375Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0066-60AE-8402-00000000C501}1716C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061374Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061373Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061372Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061371Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061370Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-0066-60AE-8402-00000000C501}1716C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061369Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.051{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0066-60AE-8402-00000000C501}1716C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061368Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:42.052{7CDEDE96-0066-60AE-8402-00000000C501}1716C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038071Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0067-60AE-5202-00000000C601}2820C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038070Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038069Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038068Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038067Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038066Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038065Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038064Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038063Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038062Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038061Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0067-60AE-5202-00000000C601}2820C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038060Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.411{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0067-60AE-5202-00000000C601}2820C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038059Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.412{266C2353-0067-60AE-5202-00000000C601}2820C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038058Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.193{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A312C6EF5E758D648581EBFCB4E79454,SHA256=6357E85CA1AA3B1366E1CC7B0DD9E3D74D07C5390CE596474A4301D01BF56D55,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061391Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0067-60AE-8502-00000000C501}1960C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061390Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061389Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061388Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061387Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061386Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-0067-60AE-8502-00000000C501}1960C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061385Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0067-60AE-8502-00000000C501}1960C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061384Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.904{7CDEDE96-0067-60AE-8502-00000000C501}1960C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061383Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:40.312{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51003-false10.0.1.12-8000- 23542300x800000000000000061382Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.151{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4218C50DF374FF05C69D6EB98CE45AFE,SHA256=84249BA45F1C40E755090ACD8D7AC4BE102F360472D6D2750A41D9B9CBC86515,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038073Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:44.427{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=326AA1A9E2A08FA8DDBB86153BE31244,SHA256=23E617127DCD08DD34558A865F954679DCD1D623162B430DD148E21D763FAD01,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038072Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:44.208{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB39436061496BF060E0ED36D30A5C6C,SHA256=C53F0129B679A4819B825F3AB30B577416B23EAB999E1FEFEBDA5B665EEAB7BD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061393Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:44.919{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=710035696F1ADB766F22EE7045BFC09B,SHA256=776C543FF41AC15B4D8E81CB6170A24F80BF34A636D64094C0C54AF39CA7A5A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061392Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:44.172{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB7B2585F885161DCA62F508FD983E4D,SHA256=DC895A3113AE7FA283A23BBCA986F21D683109B999CD1D2DAD912F4F05464D9E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061404Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0069-60AE-8602-00000000C501}2880C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061403Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061402Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061401Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061400Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061399Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0069-60AE-8602-00000000C501}2880C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061398Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.835{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0069-60AE-8602-00000000C501}2880C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061397Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.836{7CDEDE96-0069-60AE-8602-00000000C501}2880C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061396Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.075{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51004-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000061395Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:43.075{7CDEDE96-F0E1-60AD-2D00-00000000C501}2484C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51004-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 23542300x800000000000000061394Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.188{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03E83776651F2F82E9D9C04DB977961F,SHA256=2E6CECB17AADE302163FD2FEE70FE84D14936ED419304342F0AADA316A33EA2B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038074Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:45.287{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B7F59C3C3D5B911DC9548D3617E0E415,SHA256=DF99863187C5E433F25D6D4018EDD607D2E16B2D8E7937DCDB6DC11B97DEF6AD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038076Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:46.302{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0FF4BFD7F21D3CEFAF9840058BBAB74,SHA256=9F391631CA663211024A5C5F8E434FAEA27C5CCA33D35647EA86F15A5EE3A5C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061416Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.835{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DB8E0D602B83039247798A04BEC80245,SHA256=F0FBAFF33A78BD69C7FABDEB9EDC2649C81B207F6CF12DB27A1146794428195A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061415Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.704{7CDEDE96-006A-60AE-8702-00000000C501}49001628C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061414Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-006A-60AE-8702-00000000C501}4900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061413Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061412Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061411Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061410Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061409Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-006A-60AE-8702-00000000C501}4900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061408Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.504{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-006A-60AE-8702-00000000C501}4900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061407Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.505{7CDEDE96-006A-60AE-8702-00000000C501}4900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061406Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.219{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C431F09A4E8DC45A599B36CCDF95E712,SHA256=7E3E966589EA0EF5CC388D0B67F6C4729912B71B2E901E0DE09169C487874894,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061405Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:46.050{7CDEDE96-0069-60AE-8602-00000000C501}28804156C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000038075Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:43.267{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50525-false10.0.1.12-8000- 23542300x800000000000000038078Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:47.896{266C2353-F0DC-60AD-2300-00000000C601}2112NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038077Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:47.318{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A8A441079A7F9242FFD44AFCE0C4177,SHA256=D732F78EC8DCBAA6C0157F71060051B11F15BA63EA27D48C49807655A1D4996F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061426Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.288{7CDEDE96-006B-60AE-8802-00000000C501}2788288C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061425Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.236{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=66CAB04A90ED9EF7BCF2CDC63C074E73,SHA256=EB566616013C9248BD005EDFF940C15030BC005D097D610A468FCB2199135FD3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061424Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-006B-60AE-8802-00000000C501}2788C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061423Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061422Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061421Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061420Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061419Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-006B-60AE-8802-00000000C501}2788C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061418Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.103{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-006B-60AE-8802-00000000C501}2788C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061417Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:47.104{7CDEDE96-006B-60AE-8802-00000000C501}2788C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038079Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:48.365{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5BD8F3DDAACAF71CE3950291C18BC65,SHA256=BF43F6610749361D543E9727F54CF949B0F8B5A6F9A6A5847AE16C70CCD79688,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061437Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-006C-60AE-8902-00000000C501}5088C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061436Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061435Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061434Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061433Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061432Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-006C-60AE-8902-00000000C501}5088C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061431Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.704{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-006C-60AE-8902-00000000C501}5088C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061430Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.705{7CDEDE96-006C-60AE-8902-00000000C501}5088C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061429Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:45.374{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51005-false10.0.1.12-8000- 23542300x800000000000000061428Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.251{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2ECC7E81491A7675A9062A6FE1621AAC,SHA256=44E564EC541E966F6875CFE97B64B59FFDEB07256246358A77B12392CA3D4984,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061427Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:48.104{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BB8F6BF6165A1C3281C5FFEE7713E991,SHA256=6A2F3287D84E18A2F35C52E4B6A91138F50F36FEB877525EFA403FC54A73DDC4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038080Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:49.381{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2BAA3C51D9EC4C8A2F26FBAAEF5123F1,SHA256=26C143BB00B3DC61244F9B7E6E8C3DD7DB3B04480D465FA82A2DA3DEA6115AB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061439Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:49.705{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=265B6EC1924D3F39766F61CCA8980EDB,SHA256=65624C93D4EA884768D39D2CCB9C326368204191F6B1DD21588EADAB77F888F6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061438Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:49.251{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2238880193D7C5043BB040B224E156D6,SHA256=9A234A0DDD89D40F391FFFC44CB1D5F341D75E14F5413DBC1A8B95F7A130DC73,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038082Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:50.428{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2FE1DBDB9DBD75C8C32324D2BEDBF4A4,SHA256=DF765059D132B59CB038EFDEA6EB5EA589DF1DAC34E0668EC31E9B6074FB2419,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061440Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:50.271{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3AD077C3F7F258E6B1300374BA7420F1,SHA256=1B1911B5F4C44E43106B43AE3D750797F0559D00BF33D95B830E2878D36B09BE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038081Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:47.032{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50526-false10.0.1.12-8089- 23542300x800000000000000038084Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:51.490{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=596B39F682AC5B469CE266953342CA94,SHA256=4CA0710F12DCD5CD59DDFD45225C9EE746651EB2C19CB9BA8B970E7C8B2BA6CB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061441Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:51.290{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44634A249B1A5CA94CB386A0071CC6DF,SHA256=8F083288CC6B2F0207B596D5E11C984D910DD0EE5D63A6E53D1885DCEE12146C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038083Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:48.392{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50527-false10.0.1.12-8000- 23542300x800000000000000038085Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:52.537{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB35075F4F943724FFD11568B43C7E63,SHA256=107A1636CAA40A9E5B106348A1B6C6C05478BAB07F78314D4FF35FBAECF315A7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061442Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:52.304{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB198B628B1E7DA632A408DF3F047043,SHA256=46BFCF45064E49777FE0F170182607DCA096848E9C3955F4C9EC4C78ACF6500E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038086Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:53.662{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3736D375656AE40AE985F878959ABCF7,SHA256=831A763F548D7847FD5F24657429D90CADB60C13D0027943B90F6613735A3C56,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061444Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:51.275{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51006-false10.0.1.12-8000- 23542300x800000000000000061443Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:53.306{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=298255C7B42212E59E034BC518600381,SHA256=7A5E0315605C673BE3BAA9C782B97D92B5D84E5290EF4C7BD66DF994A447E340,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038087Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:54.804{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A4C9398F04E80383717E4BE68E8FCE22,SHA256=6255A7992ECD24D2D8FA863246B9FB28F7D52BB22BA2BA0EF058263658DC6369,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061445Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:54.336{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A594FD93593DB9EBE630E0BBAC1962F,SHA256=C5DC514B3C0E75AABC9459C2049D9AC8C73BBEB76DE6211C5DCFC7858E9165C7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038088Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:55.850{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D7FBF9A71C094B8DC39232A42A988A23,SHA256=72D919A21BEBEB3123D51E24F75A0F4C3F5AF42B64CB9F67FCC2AFB7562C7132,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061446Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:55.340{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=46A82E8B0AA87E8258B9F31DAF6A2772,SHA256=783F0E2171A127E188DBC22F74AFF7CD1B8B620B33BEBCE38CDB3C695BA96A66,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038089Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:56.866{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3174B7C332D31B6097C3C5F6C550E06E,SHA256=D676E3CFAF72785008EDA8888BDE8A9E46A3F4C9810FADC804FC9DACE17723D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061447Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:56.355{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D31F37B5CA3BE4681B51E2C99045B484,SHA256=FDEDC259529917061771CEA08962B0744F8BC8A4AB81FFC3DBF89F2E722BBA8E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061448Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:57.393{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=430C0397FFA69A41565EACDBB650578B,SHA256=F575A7B7C14275A0E887C103C50A983ADF9F571FB988A030872FF5B02F012B40,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038090Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:54.345{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50528-false10.0.1.12-8000- 23542300x800000000000000061449Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:58.406{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C483A7FF001948277B75090EF1B24276,SHA256=D4E745AA1C8C3BCD6E3783A991EBB92A430136E98BD7CF607988A9FAFAD8610A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038091Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:58.100{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F718EC4E85A22D4C126E04E4EEC7F97,SHA256=7F88964417CF2E1C511EF5DAB36D30330ABC4A464E6D9D1579936E80A0DB191D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061451Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:57.210{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51007-false10.0.1.12-8000- 23542300x800000000000000061450Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:01:59.450{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1F39B29A91057035539688C53908933,SHA256=F5F38C5112CCFAF33E2872AE03C12310FADA1A869790B0D7D90511E0BDC855C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038092Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:01:59.147{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3EE9697B3B4080321D443DDE5B90F622,SHA256=93B60B2254BB08F34FFC8F20798ADB8B34990A8900B2A47F8A4543922FAE5EA6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038093Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:00.381{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F6C6F8FC64FB808D2FC17FC489A1059D,SHA256=5EFD6E481BBDC71E16738A202E2E9498DD61FB5C563D7AF7F6E68B693546C371,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061452Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:00.465{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D75A349045985FC0C2B9B6BA70B5135,SHA256=9363A90EA7AA077A1C59D3AE1A7B5610F6DC6B77BD8CF43420E99EBB3ACA1948,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038094Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:01.428{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B9B442229FEBE9CABFCBC4C501B23487,SHA256=365B4861A2CE6DBE814E4D4C106A77B1B5522357B4ADEA85D3E56743519FFD9E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061453Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:01.479{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=626F7E091ECD72DFA40BFCCE61F60FF1,SHA256=B334D8AD72F410D87ED4FC21D8D59F70322737E2693CF5F87EFEF922C46B8670,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038096Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:00.251{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50529-false10.0.1.12-8000- 23542300x800000000000000038095Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:02.541{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2314A40203E82E8A6C1437451AE7AABD,SHA256=3D38689840FA46D4CF24BDCBD8245B4CB6998CA430C33ACC19A2F35AE0636D71,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061458Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:02.902{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\saved-telemetry-pings\ad1b3b8d-7bfb-47f9-a2ac-bef5e9bf4dc2MD5=346DC1FBE9ABACB4A26DE7ECEAA3285A,SHA256=CFD232B1378889E37FD13B2E5D5E43A57CA63E6F39AC0D47976FBB3236588671,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061457Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:02.849{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\saved-telemetry-pings\221bb8c0-b9f3-44b6-9a37-c40447c58510MD5=CB8D3A25A4B0CF91FD59975C9AD1A20E,SHA256=1306042CBF3DEBDFF66ED0B8440D2D04340BBC6D2C7A9B9EA68359EC8B368074,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061456Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:02.502{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\ProgramData\Mozilla\uninstall_ping_308046B0AF4A39CB_8c78bacd-dec2-4d3e-88ac-2bb6b708552a.jsonMD5=42E0F6681E6996A16AB217E6A6914637,SHA256=0791FCEE7D1362FD678B51946A81291BD1CA6FC8B9A227102E22F70418596137,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061455Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:02.480{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26A027C716B2293CC369F18F0E64298C,SHA256=BDAD8AED4B8FF70225A1DB7097A10F69D72F6B6129F85F8B41B66F4876E857A5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061454Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:02.418{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\session-state.jsonMD5=EF80FA2DBC9A58F0EBA39EAEDA826CA7,SHA256=66885C06CCBC13E7ED2162AEB7E60B19DA4A688D6D5523EF84D3D805BD20D895,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038097Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:03.760{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=944E357C06B2C7DBDACDA214E976610B,SHA256=F74B9E605A3545D6B18EA49038E1F32296491EF629BAFA9A1FDE22A5F79BCCA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061459Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:03.500{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=75E0C3DFA064D3A752FE48FD82EB93C5,SHA256=A60FBDFE42460DAEEC0F5F949F3ED561B816A9138EBFB9F55725D4385FD4D25F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038098Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:04.900{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5CC99D5D33D0125F53F4C88FF7B66A5,SHA256=3C3C49DDF0E01D277908201B3EC4C96DDF4B91423160E17ED2815F305AAB01FF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061462Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:01.554{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local62864- 23542300x800000000000000061461Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:04.516{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8B42B91E51BD48B7E0E52732A470EE5,SHA256=31EE4FB6964E873438140F440C2B24C234A4DA5D1424D62C4EF30846E7C29DC6,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000061460Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:01.566{7CDEDE96-003C-60AE-7C02-00000000C501}4140pipeline-incoming-prod-elb-149169523.us-west-2.elb.amazonaws.com052.38.70.232;44.239.250.14;35.155.6.125;52.35.57.239;54.190.95.165;34.216.131.110;52.33.45.66;34.215.46.102;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000038099Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:05.978{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B16C11F60A2376C452D254832BDC8A1,SHA256=1E2EC9F8CE4F0873B012683EBE72E4A3A82A8F57AAE920A58282C8492BF33DFC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061464Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:02.319{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51008-false10.0.1.12-8000- 23542300x800000000000000061463Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:05.547{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EED4FE438002B5A4E8D5CE56593C5903,SHA256=0AFAB8BA14AB3BDD6597AA229FA660CDA6FF41821E16035023762EF55E761D1F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038100Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:06.994{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08FA6089C88D75F535B9087B476A4026,SHA256=3D1D805D047B9027BEF83F4F924C5A40A4A07147083313149F9A16AD73488253,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061465Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:06.578{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0AC59DC2A6666A10BA41218E9593CA51,SHA256=C8ECDB51B6868F2F956238C8CE333CDB57FBAE95DDE8B09F72E39C9E5B73349A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061466Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:07.595{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FFA78B53D5E4C553BF4DAD1CD9C71C7A,SHA256=0A112E8E254B5C6F9DAA6AAB38951D443E0D183FAD14DE129890E1DDB1F4ABEB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038101Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:05.332{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50530-false10.0.1.12-8000- 23542300x800000000000000061472Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.615{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=72BE220EA9B7DD7E7BD1D0B8F0393502,SHA256=A2CD2C5803B9874BF264B25C3DCC1A457147972B2CC2F9865353F71D6BD58FAC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038102Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:08.041{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA275F2C57478DA3BA66D236BEB017C9,SHA256=69F58D67FEC7BC1D0886EFABE3170B8F5B60389936AE8C5576602BAFDA5F308C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061471Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.015{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=AC9BACCFE82E7EBF235B8578C28EFBAB,SHA256=D601C5778AA2A24DE6368EC501F77BAADCF19AE020780A9CE1F712372A4349B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061470Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.015{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=24894B012FFA2B04B6D4FB6528A0F101,SHA256=7463CFFCA01463FC656ACB2E3955CDD344E86741C9FA0A06181A75B04B22B296,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061469Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.015{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=E49E4F9DEC53070A4E01702D488F6818,SHA256=F0EC32CCAE580127A5CDCD7B57D70BEB0C03547A671EEE2370F4D12EB0336573,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061468Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.015{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=F818017D61C8D3DF67AA590851447AD2,SHA256=FFDD2DD4B8C32BEEC8E6CF80E1C317C03DDBA2E12B742DB6282B3DD0C4F6CF1E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061467Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.015{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=C751DB5F286263117658A3E68406AB92,SHA256=FF89E8697FB72EF75F73CD49E01A945CDA65585614BB1EDC6AED760A229BF60E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061473Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:09.615{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B1E1907A6DE5CB0C8F431DFB2BD10475,SHA256=54A4A04C4EA6EB1F7348EA8FAA7F6C3C72C63D01E6127C85D37EFCC34E801CCB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038103Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:09.073{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1971C722EF8521A039CB7FFFA0819345,SHA256=B4116D92570ADB6ACADE719E433DF30FA54780966487D3A18A857B7287337A3C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061474Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:10.630{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=74AFD90EF18DC95177B911C082535CAA,SHA256=0474C85E62760009964DAC46DD96D040223E2EAE9185570EEFB8C3EA06AEBA17,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038104Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:10.229{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A9B3F851C12222040317498F20EDEA3B,SHA256=14498E33083634393CB484349F36FF790DCE356154EA9F9CCAA69EE3E86C1C95,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061476Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:08.302{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51009-false10.0.1.12-8000- 23542300x800000000000000061475Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:11.694{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1FADADE712966B3FE56A27CD73558E9C,SHA256=736153642305C6A00CA79131502F14707B2627DF85CF87BA10390D88209F8E9F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038105Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:11.244{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=497759BECC29FABABA771DAF7FE85746,SHA256=D55AB827DAC69BCBAF22829C64395A5B079A02E516E695C3AE0EB65082AF9F89,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061477Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:12.744{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA5A61350886C4B5804EDD1F2481242E,SHA256=658EBEA8E2DD4FCB12E378768EA72524651F2A1F719637EDFE4B38DF3A84988B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038106Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:12.276{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67F62356F0CD02605078A26B11A3D997,SHA256=5BD5657BDE6F2E2A1F8AF831E46672FAAAA6ED057AFE4DDDB1C08C06B640449F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061483Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:13.911{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=69275393803A613E48336D0FEF50B3A1,SHA256=86D5B9423595DCD8E77D034F6AA7678C56D837DC89444D0CBAF79940E94BBC15,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061482Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:13.911{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=71933F548B5C1E1024C1E5D68385C035,SHA256=8B7BFA3B79300337F22376C674EB2F67F49E865696B53D8C14F761630AB02177,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061481Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:13.911{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=AAEDB2DC8B67457452E96C388EB011EB,SHA256=C032083192C3F78C4DCF283DB277CC14A3DA60ECD1D6CBD9E127E8EA41F5BE46,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061480Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:13.911{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=5AF8BF81DC3EDF6F323C98712AE33622,SHA256=5901892C2908AC41C46F896ACBB388B2925C8746636B2D17DAFF9EBF23DD1F76,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061479Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:13.911{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=1D70E8A7A71C4F4DB598984D5DF2C0F0,SHA256=EFAD290DBB0AD1A58219B17BBEDA4050B9B379802CC1B6D1EEF606154B075B54,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061478Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:13.759{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B217B6DA1DDADA0A22023FCFD8BA991,SHA256=A9F6D2DACB6620217F512661D7335E233D6D2EF2E2CD903E016E8E4E0425BCDC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038108Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:13.291{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76779286F40F2285033BB7085DFE1A00,SHA256=9DF3D722A59CBDB0A05590ED0E7C6D47C41F1E943F228420F8B99CF8DC131982,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038107Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:10.347{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50531-false10.0.1.12-8000- 23542300x800000000000000061485Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:14.775{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A17AF4BEEEEDD501604289ED44711F46,SHA256=763F1B9272C667C24946F75F42FD6FA4F57FADA40699E23BC9256E45391BA63D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038109Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:14.323{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A60BCCFE841C4973E12302652EDE680,SHA256=76480AC991A4E67A84095B1669EDF817767ED7EDB05890D595680303AEF5B59B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061484Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:14.728{7CDEDE96-F0D1-60AD-1100-00000000C501}388NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=9022572D669F5A512CF544FEA9040EFF,SHA256=AAF5DA89B242A39B142D90D92113E7E188223185A9DD269FF835DF5FC34B08C5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061486Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:15.793{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4E4DF30CC7B7ADC4142585AEFC0B0804,SHA256=853E7B1CF9B5887BEBE1290937B3FA4D1FE05F0C2CC806CC4B24462F4E4652E4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038110Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:15.557{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7417D5D0F2B00ABABE65C7842E9568EE,SHA256=3093B3EE333865416E208B0DD5B76E0107EEF4C836D74AAB0BA7077B2F9765B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061487Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:16.827{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC4DC71C48AA13C78F07685DF7771320,SHA256=00F6B974E6422568D25701961DC72432703BB4CE401EF82EF6F72064A3E3062D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038111Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:16.651{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32A2418D14A6EC5B8070D14352146D96,SHA256=FCD131A8CB3B0BC00898359EEC78653049E45C82EF7ADB77FA503F7422561B36,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061489Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:17.858{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A765452BDCC0F7EF33A80511A7F49B4,SHA256=10E88F1FC132C4FDF495AF679F94C836BE8042BD9FD49D0D3C049FB54EBDF425,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038112Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:17.667{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=46A8F577C65AFDBD2CD601452072A1BC,SHA256=A5E28A0C32CD208EEA5FFDF3C7C7C1538BCA1A62153B541D5821D62C19C5D051,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061488Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:14.268{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51010-false10.0.1.12-8000- 23542300x800000000000000061490Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:18.892{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=911C3A30B357B49B22FE441BE10F3F89,SHA256=36C43E181A7C9B73D1181DE2568F82890EE132D5555CBAA19A5BC31F7D1C2274,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038113Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:18.714{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05AB25712D31429F53B47A1580611726,SHA256=4774D8D3B5E4D6E05D6308B448699F5385A40ECB48D3E9387DA8C261D12856E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061491Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:19.925{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2CD6171928F39F9A5E031EE4FEFF24A4,SHA256=AD40E6626C28424D5B44175E16ACA13717DF9B1B90CDDC2A2BA7FB9CE38F2A57,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038115Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:19.948{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD650164ACB3918FE7CB1110EA5E578D,SHA256=B698F3230C2FA6AFC60E795011E063DD3A302B36B06582D4AB881A6459964D99,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038114Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:16.333{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50532-false10.0.1.12-8000- 23542300x800000000000000038116Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:20.964{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BE4A524DCD747C8961CF8111D8B25B3A,SHA256=062044B93C506D39E7685B8F9724E72F978F120F8358D5C0F3268F7C9AF7A9D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061492Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:20.956{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=258A6227CEE45E8FC23839897B9A8370,SHA256=D8EAE4C30C3B099712AF5C144740E8172F5D9E626126A17B700CF585F079AAEA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061493Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:21.989{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB8640CE6888F8948E5AC9C2B0BAA8D2,SHA256=E29619550594E6ED5800E2BF8EE486ED969461384B4F3C7A7927B06E718A1E71,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038117Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:22.198{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9108B49FD839DFC35736CDFD02A03EF2,SHA256=F91045692224B54D609F87E82096A0EDC58707E9E3B9DF13488A511C0BC4FC15,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061494Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:19.364{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51011-false10.0.1.12-8000- 23542300x800000000000000038118Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:23.201{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A7B5EFD398165EA183D5C9C11573EBF7,SHA256=FE1F4C0354F70CD4119A2A6A9BDAE9A9E401AD459D1E4A1E699489CAB1CE4EB4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061495Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:23.023{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CDBC3633DD4AAEF6993A3F12A6291128,SHA256=4D66B3B5FF201521F15D33EB6D5795C819D480D79A45A16033DE0881B2E3B2D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038121Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:24.873{266C2353-F0DB-60AD-1000-00000000C601}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=5B62C6230DEB258C26A9FA436904D6F7,SHA256=5747E6C7709E3455A6E4C3C03A859679680BDCCD7D8759876283B704EB8A3E8B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038120Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:22.303{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50533-false10.0.1.12-8000- 23542300x800000000000000038119Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:24.217{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24C03CF178B1CC8730A05BA8643605A6,SHA256=904AF0E89C2C0D1EDC3BA835DF0DF6FA31E910DC64911A75D5B1D2379A682B77,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061496Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:24.039{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B980DE834B7309D0375B9425680FD12,SHA256=5302D257AB3195AC51D3989B19C178DB5849020BAAA2E088FF7C6576AB7AFC77,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038122Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:25.248{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=86F35AFDF77131DA3C296863D2F63412,SHA256=1FBE19E6B50401FA13950176AD0A7B3E6191C00B62FD7D6714C60BC1D0B36579,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061497Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:25.074{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4E13B745ADA659BE49B19F922B2A5972,SHA256=5F05E570236C717E01C5FAB13B92A39575FCBE4159E30B04A7D000943337BA4A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038123Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:26.264{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=792136E2DA5A9B27503AE375F20E5BB0,SHA256=0D50D68DD120869141E5187B3DB9398BE31E5D46E1A3AB46D44B5504A696EF8F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061498Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:26.075{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=145095080F3C43C671BB797ED19E9DAB,SHA256=45002774ACB4AB143CF46256E4B0415967CF59680B0EEC8006A803B60D933C7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038127Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:27.436{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DDB7C6918AF9C9CE6F67A83E9339E61,SHA256=0436245CA05F8F8C4EDF7B14399CB7A7F592849767AE9B1B73CF7FE98D8BFD95,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038126Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:27.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DB-60AD-1500-00000000C601}1152C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038125Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:27.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DB-60AD-1500-00000000C601}1152C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038124Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:27.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DB-60AD-1500-00000000C601}1152C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000061500Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:25.230{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51012-false10.0.1.12-8000- 23542300x800000000000000061499Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:27.110{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9BA998AB5A9D55757C7E872912BE008C,SHA256=B828393992EEDF1AB0C50B3C1F47891822D6C6A2DA783CB4D2F6B48E3F5C101E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038128Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:28.577{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEF97F98C427F1AF892181AEC7A5B8B9,SHA256=3612FA1AA4C74E57C03175EA304916F8D87D37C5662809509E960958AE41FF4D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061501Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:28.144{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F4C9DCA77C5966B714B6A117EF54A345,SHA256=D92B9FE2ABBEAD5D754887FBD826C1E3278B01423741E9DAFA041B46D2CA266F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038130Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:27.334{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50534-false10.0.1.12-8000- 23542300x800000000000000038129Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:29.717{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D036888662E3ED7E26853C222B50070,SHA256=762C5D307723EB561B533D4F7F0A35F1FD2227F0E16E4DFD5A269AA302B713D0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061503Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:29.643{7CDEDE96-F0E1-60AD-3000-00000000C501}2240NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061502Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:29.174{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4051D2EBDF1E38D5E8CD5D301CAF8E39,SHA256=09EAF99E3787C5384023D463C0ACE79096735EBF4516337A13C5A2DB03200ACF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038131Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:30.858{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E87CCFF85ACCF77AB3664593A2836ADB,SHA256=2FACABC0848968B12CAC29E02195DC7DAA44A6ACEBA3A796525C5F01631CF6F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061504Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:30.175{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE2EEC48FA36787F942B4B4ED06B7F0E,SHA256=DA3B7D3F6B7F13DCF205E970B91355C117364E8C47B6793298474AF821B3250D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038132Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:31.921{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5247E20E3F1782C9510D44030A0B4E79,SHA256=203BCBE284B6892F31C4A68456C77083410800224691161F8B9EB446995D0444,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061511Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:31.842{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=8649FCB178DF83E533E0681A006180C9,SHA256=1FDA1C578F5A5D5FB47E110537B7865E9E73EAA4C6473BF81B7007DCA6292C90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061510Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:31.842{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=B9F8E12A765114ED7082F442C71C6047,SHA256=EEC1D7691D28E17EE6278E41BB00BD8B6E64AFC1D8F4821D15DDB8214A7296AA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061509Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:31.842{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=D59A44F9A8C29A35D342ED7F6DCAF7A3,SHA256=98E21AA1B4622A8A460D8AA424B9DB66C3EED4BAAF6997D00290AB5737FBAF6D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061508Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:31.842{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=E5E0CB7994CFF6A2B19BF3365940BC84,SHA256=AE3993A7F9B7657D645DA11FFE4C0E3426A6D10585E28C293018298B6081ECE2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061507Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:31.842{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=6C09F668D9072950EC748B88EC95246F,SHA256=167299E76BC6B54E6C124F878F9B04C37A6B6DE6BC35067EBD3D8F0848F95060,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061506Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:28.751{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51013-false10.0.1.12-8089- 23542300x800000000000000061505Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:31.190{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=31ABAF80CF6A66F12988ED0208C8CF06,SHA256=EEE241114FC29D703A8BC6C3AB748244544612D074F91F28E011A9DD17C5E19C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038133Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:32.922{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=428102552DD02018AA45C8D742F3E7C5,SHA256=215B54EEB55D98F52380D93995AC3FE9A34381841EB4D0042F5356266F45E7C3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061513Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:30.328{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51014-false10.0.1.12-8000- 23542300x800000000000000061512Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:32.209{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9973A3C23B99AC8BD0FA5658E3CDC5E6,SHA256=EB0B0FD2B876280189B81DBFFD875B533716B9E2A084FA165DEBBB1337BB9F9C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038134Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:33.935{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4507B8DE980D33B6F0900295D3EBDA46,SHA256=712F29ABCD8B4DCE5EE781287C3752247DCB1661DCE5D441BBBADB2D2ED5B62D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061517Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:33.226{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1500-00000000C501}1256C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061516Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:33.226{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1500-00000000C501}1256C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061515Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:33.226{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=739FAA40E4B15D3FDE50F7A4AF34959F,SHA256=D54BF6F2FCC9D58FE4279EA72180B2AB6A72295719723880CFA38BE0762A9AC9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061514Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:33.226{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1500-00000000C501}1256C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061518Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:34.440{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB604D8FF3891DF2F831E86B8A8D8B64,SHA256=CD90FE4A71A36FFD40912A4879B06180A0B3801F2897F9B48DEF550C1F7CFA89,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038135Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:35.172{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9E42FA006D379D6DEA4061258EF2CF3,SHA256=3F2FB8D1CDBC533C6E8C8229F37FCF6A9880848018CFAF24D7F9916BB1810B7E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061519Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:35.455{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D9C6E48CC35B9B89D09740C475BD1F5,SHA256=D2592C836016FFB6B9B29C205CD029B41079129A60669C9EA91E881D04EA4771,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061520Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:36.470{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7874712AEF41DA69D0F4EE8CB4E8B028,SHA256=F95D4C8F68D2A6732DA45C78DD8B1C0A5659EB82EB124DF804542407DBD7A25F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038164Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.938{266C2353-009C-60AE-5402-00000000C601}5962140C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038163Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-009C-60AE-5402-00000000C601}596C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038162Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038161Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038160Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038159Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038158Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038157Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038156Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038155Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038154Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038153Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-009C-60AE-5402-00000000C601}596C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038152Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.735{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-009C-60AE-5402-00000000C601}596C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038151Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.736{266C2353-009C-60AE-5402-00000000C601}596C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038150Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.297{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=816B8D36A55D1246928867EA1B9D2126,SHA256=D90133CD9880B81869A7D502E079D19F0CC29221AF2979B18368F14F9D51E682,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038149Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-009C-60AE-5302-00000000C601}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038148Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038147Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038146Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038145Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038144Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038143Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038142Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038141Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038140Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038139Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-009C-60AE-5302-00000000C601}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038138Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.235{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-009C-60AE-5302-00000000C601}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038137Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:36.236{266C2353-009C-60AE-5302-00000000C601}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000038136Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:33.211{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50535-false10.0.1.12-8000- 354300x800000000000000061524Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:34.297{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local65355- 23542300x800000000000000061523Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:37.473{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=584EBDFD132A7087F59D3490D96234C7,SHA256=058D155C756E3431F71C0A45209EDCCA8B9BD861E8D497AD4B758BDB4FCF5C73,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038180Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.375{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=355D630C747411BA11E22F0AC0F1217B,SHA256=DF8CF2A6E0E40B0B2CD70B1AA5A40BE0689E8BA2B8E46F0D4F76C4084A8DA410,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000061522Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:34.309{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.com0140.82.121.3;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061521Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:34.308{7CDEDE96-003C-60AE-7C02-00000000C501}4140github.com0::ffff:140.82.121.3;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000038179Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.282{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D7DC95364020392DB0C26AE1F5ABA27A,SHA256=8D3BF61DECD9206346E413756A8BE887F6CFF1EA25B698FBE00E13FE15CC40D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038178Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.282{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EE579A09647001736EA6F6BE2B8480EA,SHA256=826763C9BB2592D139C065690F3E19154F58B963B2609F8B111BBB4B16741226,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038177Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-009D-60AE-5502-00000000C601}1004C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038176Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038175Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038174Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038173Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038172Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038171Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038170Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038169Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038168Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038167Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-009D-60AE-5502-00000000C601}1004C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038166Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.235{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-009D-60AE-5502-00000000C601}1004C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038165Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:37.236{266C2353-009D-60AE-5502-00000000C601}1004C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061526Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:36.261{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51015-false10.0.1.12-8000- 23542300x800000000000000061525Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:38.488{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC822E753FE02462993B12D0E1A62E99,SHA256=70D05D79FE7AAED2FAFC91EC6D6BDE46827703F358675380CC2F7D5B92E15812,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038181Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:38.391{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=438B5045392884F9985AE1002A606D76,SHA256=7E5AE1C8BAC2EDA268DC9ACE45FB250F0BA109E2562DACB6FDC3DC3C684FC99A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061527Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:39.506{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C95FB1076AB1F2CB73E7492E494A96EE,SHA256=22DB9DE4F082881B171779BF3F96A0DD94CDCA08A4024B3DD4EB075BA491A618,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038195Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-009F-60AE-5602-00000000C601}1760C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038194Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038193Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038192Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038191Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038190Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038189Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038188Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038187Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038186Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038185Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-009F-60AE-5602-00000000C601}1760C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038184Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.844{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-009F-60AE-5602-00000000C601}1760C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038183Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.845{266C2353-009F-60AE-5602-00000000C601}1760C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038182Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:39.501{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5A88FC96DE6B033AFA1B7EBD559F3808,SHA256=0A9DD484B3C5ACCC14FBAAC2B2F50A2387837FCC7E4B8083A3453E0EA3B55DCF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038225Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.891{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D7DC95364020392DB0C26AE1F5ABA27A,SHA256=8D3BF61DECD9206346E413756A8BE887F6CFF1EA25B698FBE00E13FE15CC40D3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038224Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00A0-60AE-5802-00000000C601}2744C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038223Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038222Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038221Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038220Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038219Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038218Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038217Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038216Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038215Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038214Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-00A0-60AE-5802-00000000C601}2744C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038213Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.844{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00A0-60AE-5802-00000000C601}2744C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038212Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.845{266C2353-00A0-60AE-5802-00000000C601}2744C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038211Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.798{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6123140AF299C0EC0FDDFC93560014AD,SHA256=F99F5A5C081CED118B3894766C131F85D72EA3448B567CA5827E60EDFDD75B8E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038210Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.594{266C2353-00A0-60AE-5702-00000000C601}39401392C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061528Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:40.524{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0DFB616D2565EB711424863A8B30229B,SHA256=AF6DF63A67D6341F3B6ACBF703BA5670938FABF0D8C2703DCCFC2F04D06BFD0B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038209Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00A0-60AE-5702-00000000C601}3940C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038208Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038207Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038206Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038205Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038204Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038203Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038202Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038201Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-00A0-60AE-5702-00000000C601}3940C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038200Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038199Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038198Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.344{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00A0-60AE-5702-00000000C601}3940C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038197Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.346{266C2353-00A0-60AE-5702-00000000C601}3940C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038196Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:40.063{266C2353-009F-60AE-5602-00000000C601}17601120C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038228Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:41.782{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=420C66C445A5F0DB63F3CDD0D290D0A4,SHA256=205C6D110332263EB703644F19312513456F1C267B522787732719C0DDBA47EC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061543Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.606{7CDEDE96-00A1-60AE-8A02-00000000C501}22205848C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061542Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.555{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=1948C7163A9CDED73CCF3B2B8B2F88FF,SHA256=D5BD838F18343B82E30EF3446071257367B1471D1A20538959C7A31E5C6F3224,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061541Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.555{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=AF957B0195D3DC849EE9C3DE04196134,SHA256=05EF4BE840244FE957466BBC3A96142FDC5243D869D62DA840945F62C06BF678,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061540Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.555{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C57D4732C06AB829D6020433E69A709,SHA256=C15E903C4B16723EEEFFE74C2DD1B9AA09065F5949141F0D9104CCD5E53C965F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061539Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.555{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=C57C905355029F60833D45B7ABF4A7B8,SHA256=65AED269389014BCC952400D72F27C70705D4061FA013DED784636E2EE0DA5B4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061538Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.555{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=51BCA14AB0EE04983B4875FBE566EA3D,SHA256=6EB73F99AE7BE3D6A893D18438EBA8EBE4AAAB1F7354ED5C9147B78E205CA084,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061537Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.555{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=9CEC8E2C2679C61A3E52A4BBAFE5298E,SHA256=5D19463B22BEEA8B8C91A5393A7DE417B33C1EE79B41442A254A32F919E82F66,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038227Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:38.273{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50536-false10.0.1.12-8000- 10341000x800000000000000038226Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:41.063{266C2353-00A0-60AE-5802-00000000C601}27443936C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061536Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A1-60AE-8A02-00000000C501}2220C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061535Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061534Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061533Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061532Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061531Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-00A1-60AE-8A02-00000000C501}2220C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061530Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A1-60AE-8A02-00000000C501}2220C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061529Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.386{7CDEDE96-00A1-60AE-8A02-00000000C501}2220C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038229Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:42.907{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DC6E9FA15FEE8FBB2B17F62E64A0B63,SHA256=5D27756D7C46C112FED8FBED0698301ABCE9FACE0DDBC66D18C393C143FCB365,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061554Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.608{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE3F66977DFFBEC080D24975AFB664BD,SHA256=1AA94D58D481D388CB809A39D5556536802ED2A0000B138F8014A7BDDE7845D7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061553Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.386{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F115722F624C2C509CDD0A18E43766BE,SHA256=04CB92F288D7C64A6AEFC224EE55F7F0A7F266BA3871725939A603719666C2DA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061552Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.386{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6D6B1CB454C20A7904865253CC973F32,SHA256=CD07312119DAC2A192A7DDFDFBF38354A75EEBF22240A00423F059B94A8F6BE4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061551Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A2-60AE-8B02-00000000C501}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061550Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061549Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061548Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061547Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061546Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-00A2-60AE-8B02-00000000C501}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061545Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.055{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A2-60AE-8B02-00000000C501}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061544Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:42.056{7CDEDE96-00A2-60AE-8B02-00000000C501}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038243Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.923{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3B0EC69DDF9B92E51CAAC025F3883600,SHA256=B1D5133AEB38AD9DE32463066E298F38E5B80BC3DD494F062132090320B67D9F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061564Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:41.325{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51016-false10.0.1.12-8000- 10341000x800000000000000061563Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A3-60AE-8C02-00000000C501}6116C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061562Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061561Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061560Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-00A3-60AE-8C02-00000000C501}6116C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061559Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061558Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061557Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.824{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A3-60AE-8C02-00000000C501}6116C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061556Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.825{7CDEDE96-00A3-60AE-8C02-00000000C501}6116C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061555Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.623{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D07F9476ED3631D8BF5D8D97C0464F79,SHA256=86ADAB4D7917482E567854FEFEBABCCA1B2718AC7AF17EA2FD8ED10FC13508F5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038242Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00A3-60AE-5902-00000000C601}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038241Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038240Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038239Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038238Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038237Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038236Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038235Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038234Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038233Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038232Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-00A3-60AE-5902-00000000C601}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038231Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00A3-60AE-5902-00000000C601}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038230Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.423{266C2353-00A3-60AE-5902-00000000C601}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061566Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:44.870{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F115722F624C2C509CDD0A18E43766BE,SHA256=04CB92F288D7C64A6AEFC224EE55F7F0A7F266BA3871725939A603719666C2DA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061565Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:44.639{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F7F9EC3CD5C31D6C12D4C9F86812C88,SHA256=D2065A9D8305C412210889F69B8F7743D23CD6C2EC176F21F903321C44A62470,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038244Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:44.438{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E3B46396A1A8CDF3E470E1176067765C,SHA256=2CFB2796A2BB783A96A4F6937B63D6254814F234D69659D1BD9232638D128D12,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061577Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.078{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51017-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000061576Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:43.078{7CDEDE96-F0E1-60AD-2D00-00000000C501}2484C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51017-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 10341000x800000000000000061575Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A5-60AE-8D02-00000000C501}4236C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061574Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061573Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061572Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061571Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061570Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-00A5-60AE-8D02-00000000C501}4236C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061569Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.854{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A5-60AE-8D02-00000000C501}4236C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061568Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.855{7CDEDE96-00A5-60AE-8D02-00000000C501}4236C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061567Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:45.670{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D26470E98FFCC62A6F4EA0AD96D2CF6,SHA256=DB537BFC1452A345AE049E73F0ED9E044065B02C4836ED38CD89624F3C25FDEC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038246Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:43.273{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50537-false10.0.1.12-8000- 23542300x800000000000000038245Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:45.157{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1DE2E564B83E1A6CA67A57FDFB54F7B,SHA256=F559D9348FD2F6002AE08D2B491815A601E3BDB1643123ECC77B9007005BDED2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038247Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:46.392{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2869E6F84FC389730537FAA5F38642AD,SHA256=D2891B5EC72D85CE5761B0C27A2FA02480F3A912917F1B4270B31860C35FA7EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061589Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.868{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=24D88292B7DAEB788F866DED68E9AFF1,SHA256=9FC35D38B2917582999E0C9355454F31145C99B104E9D27A23E498A163DBFDCE,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061588Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.737{7CDEDE96-00A6-60AE-8E02-00000000C501}41245876C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061587Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.706{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CFE01AB86C559ABB651172FFB50B795C,SHA256=EAE8DA87CC322C3F6FDE8787EC7943157011E3B75B57892DC30B47199C185835,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061586Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A6-60AE-8E02-00000000C501}4124C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061585Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061584Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061583Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061582Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061581Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-00A6-60AE-8E02-00000000C501}4124C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061580Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A6-60AE-8E02-00000000C501}4124C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061579Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.538{7CDEDE96-00A6-60AE-8E02-00000000C501}4124C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000061578Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.038{7CDEDE96-00A5-60AE-8D02-00000000C501}42364612C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061604Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.737{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC39E37F784F3D62BC90FBB51085C8FB,SHA256=6D2DD4D5AB29449688C4B2D03193A79D8C8DCFDE99B274D70AE26FA8D37B8DDF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038249Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:47.923{266C2353-F0DC-60AD-2300-00000000C601}2112NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038248Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:47.486{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=40BAD1EB8390663C4736CEFFE840B7D3,SHA256=F30984817A69B6FA3BCB5B40B270BDC22C6FF49AF5F6B69207F6F82143408A10,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061603Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.452{7CDEDE96-00A7-60AE-8F02-00000000C501}54325592C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061602Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A7-60AE-8F02-00000000C501}5432C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061601Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061600Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061599Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061598Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061597Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-00A7-60AE-8F02-00000000C501}5432C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061596Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.152{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A7-60AE-8F02-00000000C501}5432C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061595Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.154{7CDEDE96-00A7-60AE-8F02-00000000C501}5432C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061594Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.037{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=0740ED60BCF45A09B7E0967A4B13465A,SHA256=F47C3D416070924B21F475E32BBCF192EBE4E515B44F880618968D8EAA11E91E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061593Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.037{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=48DD1CD277B016BC6F4D78DAC4CF7127,SHA256=9CFF962E9FD4B53D9BCFBC9DCFD6034DEFF52F24A12265B6A0D42364C839ADB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061592Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.037{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=B742CB024F17C70D8E4F7E614BA1C6B2,SHA256=664CB2B876D9D93F9BBA86175C025369565A3AF01ABDC1BE78D480014DF4F3E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061591Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.037{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=29D1BD0BA6B4A4639AF7EBDD31BB16D8,SHA256=D6294081095D4E643AC782176F5C71B4A74F454CD007F18FC35F4D3CC0B28B31,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061590Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:47.037{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=C4AE2509904773493523814B3164041F,SHA256=3BE571B4484FB87D7F9F47355841EDA4E90AF36EAA1D9B2C9CF2A7E9868D3959,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061614Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.767{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=33D6870848B56E1ED31275125400E158,SHA256=E921BA6A8910A52B3B23366366C955F6F3F71D4867D2C56126795C6E381F931E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038250Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:48.501{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FCAAA7793A8CED7A333837B039F7849,SHA256=8F3F0841601D748CDC3311246C7F2E44C1C307083AC6C50356364AD9267EC661,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061613Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.702{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00A8-60AE-9002-00000000C501}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061612Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.700{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061611Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.700{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061610Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.700{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061609Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.700{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061608Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.700{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-00A8-60AE-9002-00000000C501}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061607Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.699{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00A8-60AE-9002-00000000C501}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061606Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.699{7CDEDE96-00A8-60AE-9002-00000000C501}2564C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061605Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:48.168{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F266F26FA11E3BA06DB8161140A2FB65,SHA256=C82967557A755318B2EED48F56369A7089120DFB466552E8BA76D6F10DC71410,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061617Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:49.782{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0668A08E47CB2645C992482BF9C8B755,SHA256=92F759A968CB2FC27D68D2C0BFF4334C63AB95044FA046F3F3CB9BD428FE0B6F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038252Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:49.517{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D8950586E53E3CDC6F618683969672DC,SHA256=154446214A9EF9474D148D486BE5629268A90EA02E2DFF1E416EC2D562A2E3BB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061616Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:49.735{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BBC90FB6E82FFCEC33E332BF3C8867CC,SHA256=58D538DFD7A37797B2E24E665F0901DE224939194A4CE25D5DF73526C44B9951,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061615Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:46.344{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51018-false10.0.1.12-8000- 354300x800000000000000038251Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:47.054{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50538-false10.0.1.12-8089- 23542300x800000000000000038254Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:50.533{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3A526363356F32E9FE5B59EE4A5107E6,SHA256=5D6921C2D5A7210E41FDAE18756A5FA31AF19F0C1FB8AE7C143A7ADA9C689CAA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061618Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:50.799{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B4887421DE7EF26CF70B89265176BD3,SHA256=0B775B14700689BFFCC733EA0A46C0649743224C06477A879A46ACF1AB63E7D1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038253Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:48.320{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50539-false10.0.1.12-8000- 23542300x800000000000000038255Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:51.564{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=47BC851BACA86FE3F4A6BF9A1CD93467,SHA256=FBB8181FB35E579119A65FE7BF8A5DDF6CB56D2F75816B980D6B60FB53CDD5E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061619Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:51.833{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=374932EDCAD80D64FDE5ABEC4B084768,SHA256=34B2619369F3FB408010A3966043BB4F32B82542B4FA384ED6A6F549BA678163,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038256Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:52.580{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F2F1E7464E2F1B9DAD0B2801B3A0FA03,SHA256=248B374E45CF4C05722387B584FAC3B5EBF02C944E08973AB6676D556854C757,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061621Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:52.847{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C0FA60023A95E047322C3F4348FC333,SHA256=0C3246B8C68901009337C379EE32F61F745BA230678A7BF4C55D6A278B178E5A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061620Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:52.648{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061626Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:53.962{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000061625Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:53.962{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000061624Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:53.877{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061623Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:53.877{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 23542300x800000000000000061622Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:53.862{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4361CEF76649C1CBC4918A20B10A7A88,SHA256=97F5BD7EC134D599CE02F135740529D6F8A9046530D9C32FAF6B7D691C1FD1C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038257Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:53.814{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E86FF00E88D3EFFD2D891C4DC37E71B5,SHA256=5A7197A9E096F9C37F873FEC85C398EB6FAEEE4660A821A89B2F7D7160D5E6F2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061627Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:54.864{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=66FE1EF8DFAE6250CBDCBAEAECEA098F,SHA256=0E06BBD3695B4E855A2DF4840D41BCB219C87F9B165DAB531F49260A8C0CAAF7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038258Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:54.830{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4514FFC2FDAE99DE33053D52E2291E95,SHA256=D7ED362C9B3C37E23793784A361EE845B0C25D34D0F625454089C40A54F6FDE4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038259Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:55.861{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1E294E56478B2111E81A8707F67DF6F,SHA256=751F9B47BE3982A1DDFB0FD37CD4AB04AFCC95746F30E1B2E15395F916B09D32,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061631Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:55.879{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9B813E39120066FA27191D9C43811087,SHA256=09A083469CD68725EA7333230679F80413F31F63FC6784703ADD568D360C6E1E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061630Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:52.270{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51019-false10.0.1.12-8000- 10341000x800000000000000061629Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:55.017{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061628Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:55.017{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 23542300x800000000000000038260Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:56.908{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF6D3C089BF318A4A1C496948F7E98A2,SHA256=18F552BB07359EBC60EFD1957B013A445E3AB336546CD564DB18558951B8EC81,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061632Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:56.915{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=31D6852B4B239EC991BB90AB402CBAE2,SHA256=712BB52FEFED6302BD3BAFA5738EE316CBDD0E643DE0473C1E7C57813C321CA0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038262Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:57.924{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F246F6AA2FE0E47CEACF97206657962,SHA256=1493151DE1F0ADF6C8C08937287EAAC48D8BA9B2D24E51D0C46AF80D112232C5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061633Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:57.931{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6ECCF822DCFAF248DD7C99276BD0CBB9,SHA256=BF1A3B257EED0E3EA021C3B21FB7ACC14897B155DC8C5F5855783FCE8F9635C0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038261Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:54.258{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50540-false10.0.1.12-8000- 23542300x800000000000000061634Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:58.947{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C10ED565CF9C31671DEDB91E683365F,SHA256=8279985E80511E2755B35CAA7BE39662CBECDC4BF5F163E565817C4D4D2B2CB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038263Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:58.924{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDA2CEDC0C2853B87FA0B2547733AD72,SHA256=1891948C00E6A1136652CDD363B9B910D5189CF53A79E7A8890AB68EAF3C519A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061635Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:59.977{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC209C13F6E3280F28C3ACB3F6A0E38E,SHA256=A1546DFEC792A8BCE0BC8D8B67A10F5A9F6B89CAB07D12DBE67405B636B0E822,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038264Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:59.939{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=998FC7A3C6EC02743AD5413A44765F98,SHA256=89611F786F9CD9974F1BA4BB2D8D86943AE3D5569F0CDFCB09DD39C87FA0B995,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061671Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061670Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061669Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061668Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061667Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061666Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061665Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061664Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061663Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061662Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061661Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061660Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061659Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061658Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061657Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061656Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061655Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061654Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061653Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061652Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061651Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061650Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061649Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061648Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061647Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061646Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061645Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061644Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061643Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061642Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061641Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061640Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061639Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061638Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061637Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:00.676{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000061636Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:02:57.339{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51020-false10.0.1.12-8000- 23542300x800000000000000061672Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:01.476{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8EAE364665D116A60A0D9D63692CE66B,SHA256=88AF631DEED2F0195E86A76AC18C9D76894C75BF3F6A21349243AD48889A00AB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038266Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:02:59.398{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50541-false10.0.1.12-8000- 23542300x800000000000000038265Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:01.049{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18B61D8C81A8C9F7EE80F0B08DCA7B0B,SHA256=F9E3D13EA725B4B59FC67753A2C2075F84CF5F32016D65865CCF5424DFEF4448,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061678Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:02.760{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=92E81C57F4E705298DF495070FCAB2F9,SHA256=91D0EAF4A5E0F7776D9BC2A46CA02AFBF252AE480A6A2887DACE2989E96CE2D8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061677Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:02.760{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=5D3A25F4D0C8F75E09EED47AC97249A5,SHA256=87BC49D6135267377CF2862E7765C5AA05807440C9751815B4F88E26732BFFEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061676Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:02.760{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=530D7E5AC47D644A50533C701A613E52,SHA256=9616F8A8012DFA81AF6078EA203AC0505C71719548B56565B5DDF8FF829A2F61,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061675Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:02.760{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=28A39982CDBB78948290409E10F20057,SHA256=63D39ABA011216601D4DB134A36BC6BDD2E5ADD8DE09DD6F1F7A92E1AD046A2F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061674Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:02.760{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=334B7817E6726DE7E3D187F0E04B17A4,SHA256=DA5EFF3045FD5D57A6D34C7BF135BA0A6A47D2B90663388D1A9DF524112FEE7D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061673Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:02.494{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0BB6FD8961D6802E12EE5EE53E754C9B,SHA256=C9D38812E119E1EC2B89D1FB11C942A81D3988AB904260C9F6BCB05B3EEA8BF1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038267Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:02.190{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6618AE03D3F125CBA84797AE3D6B169A,SHA256=88C044471584C42BF65402012132725F6614CE24BD42AEDB4761B28535F7D4E6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061682Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:03.696{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804664C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+6497|C:\Windows\System32\SHCORE.dll+6387|C:\Windows\System32\SHCORE.dll+62fd|C:\Windows\System32\SHCORE.dll+620a|C:\Windows\System32\SHELL32.dll+a56d0|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF801E4CE48C8)|UNKNOWN(FFFFFE2B934B4A68)|UNKNOWN(FFFFFE2B934B4BE7)|UNKNOWN(FFFFFE2B934AF271)|UNKNOWN(FFFFFE2B934B0C3A)|UNKNOWN(FFFFFE2B934AEEF6)|UNKNOWN(FFFFF801E49FBE03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+a8f2b|C:\Windows\System32\SHELL32.dll+6a98a|C:\Windows\System32\SHCORE.dll+33fad 10341000x800000000000000061681Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:03.696{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804664C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+1c0e5|C:\Windows\System32\SHELL32.dll+a51b1|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF801E4CE48C8)|UNKNOWN(FFFFFE2B934B4A68)|UNKNOWN(FFFFFE2B934B4BE7)|UNKNOWN(FFFFFE2B934AF271)|UNKNOWN(FFFFFE2B934B0C3A)|UNKNOWN(FFFFFE2B934AEEF6)|UNKNOWN(FFFFF801E49FBE03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+a8f2b|C:\Windows\System32\SHELL32.dll+6a98a|C:\Windows\System32\SHCORE.dll+33fad|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061680Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:03.696{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms~RF3eb8d2.TMPMD5=28198BEB5B67F751850F7449B5EEDF25,SHA256=F3FE6D27797CCF657B5A0E08D2A4E1FE1C2B10663A2CD9735465B1F9190DF436,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061679Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:03.543{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=22291D6AF55E10C18A95AED8CC5700E2,SHA256=3824510E2EDC91F7B7589FD325CBEFD66812FB20E98ED47D844F636A451078A5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038268Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:03.327{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76F66225E647B17DA603A117E14F1907,SHA256=92DC4728D93CEA90D2DD2EDAE34705AB688441F5865C8B69907884B694723E56,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061683Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:04.573{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD3A612333412B6C7080ADABCC710DE0,SHA256=B35E70691B02C2E4B05CC3ADCDF2488ED8BF2DFF7666E03EF0FF8DEF52DE7C90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038269Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:04.374{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=30CC4007AFBC039D4B90454396ADEA20,SHA256=880579BD258D4E04DD48E96AD63D9501B48D87D9F759B99EAFD2F7C6D6384B3D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061685Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:05.595{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=416636BFC50E73E7597B0CE7F4866352,SHA256=FB3F38E932F7E67F4481E4B176975C8B41C3BBFC15B478DEB1C52AF06D6F81D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038270Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:05.390{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E9C497986B3FE8841C6822524DBBD88A,SHA256=B48A62E77F6C0A45CCB5DCB3CECCEDC89E62985F73FF5CDBEAAAFA95E1EC5134,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061684Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:03.315{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51021-false10.0.1.12-8000- 23542300x800000000000000038271Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:06.640{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2009D94B16B551FB0C7C82AF53F9228D,SHA256=2985ED921824817D5AAE574B32DF94386231F465F8E4C543C7B8D5852AC86B51,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061686Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:06.610{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F387B7B0F669C1F6B2623FC58434DBF,SHA256=420ACB5DCD531C7091C78E7DC8EF05866A9DC79B5A02F52E71E767E977D162FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038272Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:07.781{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F1DDA72F80F121A94E8242D8882F39D,SHA256=1EFC4DA073B722C8FA521C5663996D1A25D52DDE91B35CFE93C0E83E78F9A35E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061687Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:07.625{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16C46416AB83E8857E41212370C39C13,SHA256=56097264DEEE65F316BE6E6B04ACC94EF9CE75E18AE90E25875427EEEA5ED5E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038274Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:08.796{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E360A6B151E93568C866BBFF11D2F335,SHA256=80660EE95DE7631555C9D9D3B6FC7E4F479F16FA3AAB4A99807A31A3CCE188EF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061688Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:08.626{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C1036832F40C0A1397C515652ECE5AF6,SHA256=98E7ADF014FEAFB2D6D0CD3922C97E6C14EB551FB3EABE07A7A17E1CF81312E4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038273Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:05.160{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50542-false10.0.1.12-8000- 23542300x800000000000000061689Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:09.641{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3D8C8DDC53F5DF3AD3E023E9209D6902,SHA256=0C7BEB75D63B2397DECF1BF02A2DC17D669662F8225A3865BBE162B8DEEC7145,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038275Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:09.797{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A95F786A98D5E6937751170A7F78AA6E,SHA256=A398F1327284C2ACD0F89266D191E597E483B75C1F702E413CAAB78F0863427D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061690Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:10.690{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3425DD296A274FA5AD374CCBACDD1FB,SHA256=6A78469456AEF740BFDE9767BBA48DA5D190DC5773422CD8CFC641A10FFBFEE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038276Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:10.812{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=42FA30C8F06CFFBEF50EB36D4E09A8FF,SHA256=889C6A71A0AE4F8E7EE9F93401FB0C1F416EA0580EA97BA6ABAE6C4A42B75D9E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061692Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:11.709{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A29B7EBAC83D58320EDD8AE3D0BE3DF,SHA256=8D60E8BEF2661D8B0835F9F3F0B3E979B86F1A95CA9B9153691C7D3F3407A0CA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038277Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:11.937{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C7E497185766B88224D0A5B28E2480A3,SHA256=9E29B7F8A9C5EB647E97423D185A35D1F3E9C41B5271A9AD4F7F0975F6038CF0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061691Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:09.347{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51022-false10.0.1.12-8000- 23542300x800000000000000061693Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:12.725{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FBA63CD4B56B95400F56FDA34DC7765F,SHA256=B1116A43301F21864B6D27E563A6859B3A395EB9962156ABDC5A72F09EB34DCD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061694Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:13.742{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E7C47974E6070D83B65A4B79AA44C25,SHA256=841D23FB79C870B126942352BFFD98EE62573F6942C7DFD4DD3940024B622B0F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038279Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:13.063{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=13CB32D487A8F4BD7C86EE13CD110D59,SHA256=46C775A0A69466DBFEA738BDB5701F21DCAB909316CF339E6E5D412096634BB4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038278Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:10.379{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50543-false10.0.1.12-8000- 23542300x800000000000000061696Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:14.773{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=850787E9DC03315A586B2AE9C3047ED9,SHA256=A8941863F03C8DF297397C493384814C93562CEA1808B265D57DE702E8E7D797,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038280Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:14.219{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=12AF10D299DB289C435F85E557CE18B3,SHA256=47F5F1FA31C2BD5424EFBCD935631052B47AAD3EBAFA08CB74EF3DD9F40902D1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061695Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:14.742{7CDEDE96-F0D1-60AD-1100-00000000C501}388NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=6BDCD8F1F124A1C1067E8C2879347F01,SHA256=E0D315851ED93680C2C36249434DFFDEDE402C333CF8337826AC0CB7E3B4A484,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061697Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:15.793{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98CC634F253ED2D8B6369C8E38ED967C,SHA256=0FBD5111459D268A371AB918883AEFA83EF3136847FC7FF584C79031378B5686,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038281Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:15.437{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=652A16756FB37BFE71370333F644E775,SHA256=812FE7209C18BE43CD508647602093E558D8458D00299C2AE4392A333DE25A94,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061698Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:16.808{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E23BC0F2CE43F271B99870FA3745C26A,SHA256=D956FDC71C96494660D9B9BA48963FDB9DC61CEBE1A9A37749FAE3B435C79194,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038282Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:16.453{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8269245FC19BB4EEF6FD1D45CBBB37F8,SHA256=1334CBBFEF7F59A7BED09B022B9F89EC02836DDA24E3967EC905B94752B677F0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061700Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:17.839{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FEA1513A38AD442472453869D2115D94,SHA256=4222C011D03E2EBCCE90E091F18B0265557A8FDE2EDEEB9A836C6839FEF691D8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038283Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:17.469{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8BFF1A96617D38AB74DE9EC0B448D66,SHA256=C7A29AD8D1A6AA7EC1DDB3AFBFD42307A697B02734A2B0486F33C71702FABDAC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061699Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:15.194{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51023-false10.0.1.12-8000- 23542300x800000000000000038285Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:18.516{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27C67678D0AEF3025DBB0B62CEBD825B,SHA256=D76B55A2344C3EF1526135DA90C027E0B9E17FB5C5D27D0E9749685984EDEBC8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061701Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:18.840{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=56AB352EBCB25EC29B48F692FB8EA636,SHA256=003FE6449425BCECC67F341E22EE706C606A2D7BAEC71DD5C0CB6C8762DCE5CF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038284Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:16.207{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50544-false10.0.1.12-8000- 23542300x800000000000000038286Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:19.735{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44E1A6C7EE3FF1593324A1608F06EC90,SHA256=58E3238FF7E7C3AF475F892A45AC6038FB68CFA01E698C4EFFBB3F318BFBE15A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061702Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:19.840{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A54C31E7A6921BB03CC2AE85E8764B92,SHA256=04A2EE05BE606E88AD377881CEE4D6FAFFDAF4F7262C8FE3243924F569E83178,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038287Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:20.797{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D339366D1C51E6B15A1D9A382DFFB21D,SHA256=C6CF02D9AEBA0D91843A0A82BFC0D1CAF2F5DA75974C01440A1D35038D0D29DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061703Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:20.871{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F7B97262CB283671ABF53E1C2469654F,SHA256=5727BAE2B547FA25AC9683E8253404E64FDC5F3D6619F3DB9A85986BA506FF90,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038288Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:21.969{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=461F13DCFDEE0223DABC094737709553,SHA256=E11A4C32AD817FDD0AD5765722EC8C4634ADB3D947399B6A97E240231900EEA5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061704Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:21.889{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=741DBA8164C332F31D2F591E47647552,SHA256=6C1BB3923C84672949C71543C7C92ED6B434C40085C8ECD5CEC78BE460F74A78,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038289Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:22.982{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53A3FB14C6BE3C9EFBE4FB4C5014C687,SHA256=44AC51B49F6E9ECD65F826A4DA2F8FAA35A61EC2A37F80E82EBCD0BAFC338969,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061706Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:20.361{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51024-false10.0.1.12-8000- 23542300x800000000000000061705Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:22.908{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0CBCAA85C649D1CF1F2BD940BCEB1862,SHA256=060A98C174690C3FC22E8D85E770EC89BEEC535BBD5ADCBD5C0AAF7E33C3E426,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061707Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:23.939{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E301128278012CEE2350108B40E2D531,SHA256=17C9EF47A565644F0D2B34D52D1230606EA321A95791C201D0540E52F576E647,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061708Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:24.954{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50FD44B20BE01A03C6D04A975FB9886D,SHA256=B8F36B9C668D8F3B91CF04255E7D9CB6489BC9CF36B35FF3F5A04AB7AF0F2BCC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038292Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:24.888{266C2353-F0DB-60AD-1000-00000000C601}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=3F27E85F4CFF0D7C07D102E55D880141,SHA256=FDCF58580374FB1A45433B5A51465F4D9DB6B3967660D406F8F7A302553D57AC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038291Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:21.395{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50545-false10.0.1.12-8000- 23542300x800000000000000038290Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:23.998{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=34934C95C10BF246E86E33D9BAD73321,SHA256=8A62FBAC3518B2561EB060E708F786C4003E4214A0BED43D15A62744204D2929,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061709Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:25.987{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02BA207C71D0806E3C6242AB3ACBCF0A,SHA256=C5DF3BBEB287F50EE8CD86237C99178C7CB3C17480ADB1B942941832F5B0C36A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038293Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:25.013{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C67345304DF7B7C940AD70E0DE5F1D3E,SHA256=E524C8AB9DB87F34F819C754738082BCA21E9C12A78A6B6FB3AAFD19CBF68CDA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038294Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:26.029{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A38EA622EC25B554203D6879DFB33FD6,SHA256=A7485B9227A0C58953DC02AA9008FCEC385F0ADF030C1A4AEC0C54D0BDDFED15,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061710Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:27.023{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=926DF1E8BCE708A81465DB21F224D3D2,SHA256=FB89AA3E20D9AAE0C8929D312C8A19052977643002D8B9A5FDE1278B99C1034A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038295Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:27.107{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=22A9309F7516DF528F081C2BD30F4181,SHA256=EA66C76DDD57F043CBD98F7D1927F63E550C641CF0F5DC5AF518475DF64EC837,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038296Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:28.139{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0FAE3249047854CA1250DF1623D22D11,SHA256=B28993B581AE9C1B7E799E809DEB0A40ECF192D74E286C301EE29976B33D6D25,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061711Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:28.053{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24C0350CA22388364E1E933758C1DBFE,SHA256=2B945FAB2664A129C36A985CEC529F42A12F7E75029402CE06A881DC021A002E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038298Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:27.407{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50546-false10.0.1.12-8000- 23542300x800000000000000038297Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:29.154{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7147E2EECF365C45DA734D239A395489,SHA256=B82F0CC77475F315F2BAC80B337E80F5E799052341103198D9283BBF5D32026E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061714Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:29.668{7CDEDE96-F0E1-60AD-3000-00000000C501}2240NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061713Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:26.192{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51025-false10.0.1.12-8000- 23542300x800000000000000061712Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:29.068{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9C790CBED9993DDE83621E9D5F41B2E1,SHA256=FBEF118636BD160865DF0900E88E59A2CF7B9A031E2E749DC476B87D1354FBC0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038299Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:30.264{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FCB8693E0FA01140D9CBC7109334CEB9,SHA256=802A78B39EF420BB05AAF50862953FC6CDE1A7054C90ADECBADE750195BE0335,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061720Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:30.087{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6B6F1DB9B6DD43987E7D5E09430BAE45,SHA256=DAACAB25EDF6D3C71A2FA69752582973FA96A83DD85A8BD7D43D59835A375959,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061719Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:30.005{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=A60BD31ADACC0ACDF00DB736411095FC,SHA256=4289B467254E30E16D5A1206B82EDC414EFF08BBF0BBD6D9E6B5B0FF85FB1BC7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061718Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:30.005{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=CBC791A4CB48F6C011B4577D6D673933,SHA256=C42A30ED595C531264A0156C3E05D9B8DF758C6597E883616A3E0CDBDDB6B6E6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061717Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:30.005{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=8F7480E39F28316905109D16B57629EF,SHA256=FED2B18BE592517CAF4C199E363F61EC9936A14FAF670F343A0DB15B3760D212,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061716Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:30.005{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=9DCE486502E2C1F7964D296180B98F1E,SHA256=4EC5C486981EBF74BC49B6EDB5A60118300401042A6AF3851F14E178E28C410F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061715Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:30.005{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=CA674DB90315D62352754DBA2050002A,SHA256=8A59B2370CEFA5494E2571460446A934511AF50B12590FE40BACCBEE4ECF6EC5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038300Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:31.467{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E11558C41CE9E832640BFAA42D67E94A,SHA256=BC6E93ECD2CF7672581503CA16D8F84C2833DC3467FD3746F5AA468398B2C7BD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061722Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:28.774{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51026-false10.0.1.12-8089- 23542300x800000000000000061721Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.104{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB32081878947568CA40F1A22B64D0A5,SHA256=F5BA5D263B769AD14E16B65B41084810E5DAF04592E45A13FB7F67F3E7F25D9D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038301Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:32.608{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=665F0CB818A278CD758608D762E80D6A,SHA256=5E9074E4F56EC55CA178D4C190EA04C41F7D5A5BED7389E94BB658D29AF6CB32,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061724Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:32.919{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061723Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:32.135{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D20B2C2E208FC76F2864E5B97FA3C551,SHA256=8148367F27886BD9677315C6462297658FE342C080A07A070AC02B37D4CEC553,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038302Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:33.736{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C47D430BA5C1E1AE598F26EB727D72E6,SHA256=09B4E5A3992D48BCA30C73BD50E0C75A83D46E3735C0B39D12745E79E2F073B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061727Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:33.734{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061726Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.206{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51027-false10.0.1.12-8000- 23542300x800000000000000061725Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:33.184{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AEBF030D4E63E7E3065254610EA4C2C6,SHA256=D156DC456AC0E3F8C8CCF32C2CB5DD78F6F2A5CBA83F23095DFAD43532916862,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038303Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:34.889{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C2255865D1B7087A2D5D930C0A52F135,SHA256=749822305D1A86B929F125F5C2007991EBC1790C82D9ED82EEC38DE8A0DFCB8B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061734Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.749{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58754- 354300x800000000000000061733Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.731{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51839- 354300x800000000000000061732Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.556{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local51028-false143.204.202.86server-143-204-202-86.fra53.r.cloudfront.net443https 354300x800000000000000061731Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.542{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57670- 22542200x800000000000000061730Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.762{7CDEDE96-003C-60AE-7C02-00000000C501}4140d2nxq2uap88usk.cloudfront.net02600:9000:21f3:bc00:a:da5e:7900:93a1;2600:9000:21f3:e600:a:da5e:7900:93a1;2600:9000:21f3:b200:a:da5e:7900:93a1;2600:9000:21f3:b600:a:da5e:7900:93a1;2600:9000:21f3:8e00:a:da5e:7900:93a1;2600:9000:21f3:8c00:a:da5e:7900:93a1;2600:9000:21f3:a600:a:da5e:7900:93a1;2600:9000:21f3:4600:a:da5e:7900:93a1;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061729Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:31.761{7CDEDE96-003C-60AE-7C02-00000000C501}4140d2nxq2uap88usk.cloudfront.net0143.204.98.30;143.204.98.118;143.204.98.36;143.204.98.120;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000061728Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:34.203{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=686D6C8EA581C50C98B329913DA2927F,SHA256=695293D9BF6B6AD6DCBC513DC81068CB261B35035CFC89359706249363DA7966,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061735Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:35.218{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7948E615909CF6BC0201EA322F0063AF,SHA256=67867788D64AB639866EF651D6723C5239624C41DDE1CABAC315CF535710C27A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061736Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:36.248{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D286E0AB3358CF187C741497BE738F56,SHA256=17FF604D9D353D6F66C18D6203D895F96646A525CF80947EA8B0A3E1A09A2104,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038332Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:33.392{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50547-false10.0.1.12-8000- 10341000x800000000000000038331Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00D8-60AE-5B02-00000000C601}572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038330Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038329Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038328Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038327Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038326Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038325Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038324Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038323Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038322Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038321Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-00D8-60AE-5B02-00000000C601}572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038320Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.798{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00D8-60AE-5B02-00000000C601}572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038319Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.799{266C2353-00D8-60AE-5B02-00000000C601}572C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038318Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.329{266C2353-00D8-60AE-5A02-00000000C601}12083104C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038317Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00D8-60AE-5A02-00000000C601}1208C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038316Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038315Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038314Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038313Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038312Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038311Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038310Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038309Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038308Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038307Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-00D8-60AE-5A02-00000000C601}1208C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038306Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.126{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00D8-60AE-5A02-00000000C601}1208C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038305Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.127{266C2353-00D8-60AE-5A02-00000000C601}1208C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038304Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:36.001{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C379B7C6F2B76B654E0F9DCCEF411135,SHA256=6FE3AF3E312A12B56035FF8EE69CDF7EDCEC5AAA4A12AC49BD8AC46428DB6FE2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061738Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:37.432{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\666x5nua.default-release\cache2\doomed\19040MD5=ACE35F64F98E4674F3C15F816EF759E9,SHA256=5F9F2C369F7A6C8F72A1A2F2329FE51AE550CFC3A58EADF5B4D62D65F7F80927,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061737Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:37.264{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5911797A079B310AE5D019C09641AF58,SHA256=E8339B86524D35228E20A2CAA81D2A4246DB3BB2CEF2AAE0A3EA1A54B0865F4F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038348Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.329{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B51A31007E309F70F7BEF44C77C23D58,SHA256=7A8296DC5402E24686325ACE5F6165468224B52EA0E2EAC66A017690ABE949F8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038347Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F51650E0C1DADE53FF7701C4D44EF565,SHA256=1C5E2FA50BD5838EC43029009DFAA43F417BD06B9D14920FC7889FEA1BA16DDF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038346Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1710759A7DE48746324C789FB6A1890E,SHA256=F5A1579043EBB9ACE368274757C9F9E657BB6E60B7A1ED4A8DF335F152007D80,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038345Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00D9-60AE-5C02-00000000C601}732C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038344Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038343Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038342Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038341Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038340Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038339Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038338Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038337Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038336Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038335Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-00D9-60AE-5C02-00000000C601}732C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038334Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.314{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00D9-60AE-5C02-00000000C601}732C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038333Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:37.315{266C2353-00D9-60AE-5C02-00000000C601}732C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061740Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:36.300{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51029-false10.0.1.12-8000- 23542300x800000000000000061739Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:38.282{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D922B94BA57E9D9BA60ADC8ADBDE24D6,SHA256=E2B51DC7FDA7CF72A0F605520D51E273E123C90149DB15389BD5433CA2D68456,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038350Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:38.439{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B51A31007E309F70F7BEF44C77C23D58,SHA256=7A8296DC5402E24686325ACE5F6165468224B52EA0E2EAC66A017690ABE949F8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038349Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:38.329{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C74D841657058838210825A688A6343,SHA256=3C6B6500FF29D41058BF52B9DE6F86972BCC52FF067E7376F3398FA8F924F977,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038364Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00DB-60AE-5D02-00000000C601}2100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038363Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038362Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038361Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038360Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038359Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038358Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038357Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038356Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038355Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038354Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-00DB-60AE-5D02-00000000C601}2100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038353Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.798{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00DB-60AE-5D02-00000000C601}2100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038352Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.799{266C2353-00DB-60AE-5D02-00000000C601}2100C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038351Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.376{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB90DEA8686FC799C2CF9465C5765E55,SHA256=220008FC3640EFC8BC95DDCC1451DCE9F14F96D267158B7D244710436F6884A0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061742Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:37.085{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59575- 23542300x800000000000000061741Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:39.300{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD8016AAF04FDF9C8F2518703054EE5E,SHA256=7786554AD3083CDBBEF4DDCD5AAB7C4212D931BC959F2B52E683D56A46374133,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038394Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.830{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D75FC5D77E34E3C8C2B669070E29942F,SHA256=4BFBCEA0F5197562D563C2EAB55F7AF3D6E55196443E8D112E34D6E062D5190B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038393Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00DC-60AE-5F02-00000000C601}1324C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038392Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038391Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038390Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038389Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038388Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038387Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038386Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038385Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038384Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038383Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-00DC-60AE-5F02-00000000C601}1324C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038382Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.798{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00DC-60AE-5F02-00000000C601}1324C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038381Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.799{266C2353-00DC-60AE-5F02-00000000C601}1324C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038380Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.720{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC0F2E3FDF73E048B4196D0E74D864FC,SHA256=D0ECB910B0615DB42908F077A02A77380310445052EDBAACF2B13C9B8737423A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038379Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.517{266C2353-00DC-60AE-5E02-00000000C601}7283488C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061743Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:40.332{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DBEB32A0FCAC2CC603A1AFE0F37AAAF5,SHA256=17DD2905C404C98C8AF8C0ABEB6CDC4EAEAE7456DB71C931EE71565B10E53B1F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038378Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00DC-60AE-5E02-00000000C601}728C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038377Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038376Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038375Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038374Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038373Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038372Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038371Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038370Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038369Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038368Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-00DC-60AE-5E02-00000000C601}728C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038367Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.298{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00DC-60AE-5E02-00000000C601}728C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038366Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.299{266C2353-00DC-60AE-5E02-00000000C601}728C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038365Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:40.048{266C2353-00DB-60AE-5D02-00000000C601}21003340C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038396Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:41.736{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDADB8AE088017BA02EB740E818FA09E,SHA256=3CFCDB91B243D4964403A8F82D8D9D9919EB20F36CB72C54532FE85D552CDA80,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061752Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00DD-60AE-9102-00000000C501}5716C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061751Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061750Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061749Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061748Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061747Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-00DD-60AE-9102-00000000C501}5716C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061746Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.383{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00DD-60AE-9102-00000000C501}5716C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061745Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.384{7CDEDE96-00DD-60AE-9102-00000000C501}5716C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061744Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.361{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A123993CF8683EFC0618166EAB225D3D,SHA256=A1D9D905E337C7C0FE2769893ED201C95D3EA421D73C27691F35D25594381F66,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038395Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:41.064{266C2353-00DC-60AE-5F02-00000000C601}13241184C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038398Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:42.908{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=996176221E6F7C5E47E543FDF31F6C1E,SHA256=2D224C4B844CDA8BF54621161B1644FD41E0309053603497662C153D8680E1AB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061764Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.415{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1F94FDC3E1C66C5C9B3480DC41C6167A,SHA256=6848B74D7D262232EF2B199C38B2B90DE13116E78BB46887933B1A85767990EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061763Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.415{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F20696BB66FC4A8FD8D6054486146F70,SHA256=43014553F5131F5A9329E51E04669277960E75ECCDF4F1157261E8FDE6F8A081,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061762Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.362{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B235E57B3AFD76EC15885ECB50C54B64,SHA256=6618655B75A57F44271F4E8ACA5C13CDD5AB2432EBDDF4A256980FDBCF2F4BD9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038397Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:39.394{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50548-false10.0.1.12-8000- 10341000x800000000000000061761Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.315{7CDEDE96-00DE-60AE-9202-00000000C501}46161144C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061760Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.083{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00DE-60AE-9202-00000000C501}4616C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061759Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.079{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-00DE-60AE-9202-00000000C501}4616C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061758Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.079{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061757Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.079{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061756Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.079{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00DE-60AE-9202-00000000C501}4616C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061755Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.079{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061754Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.079{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061753Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:42.078{7CDEDE96-00DE-60AE-9202-00000000C501}4616C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000061774Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00DF-60AE-9302-00000000C501}5856C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061773Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061772Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061771Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061770Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061769Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-00DF-60AE-9302-00000000C501}5856C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061768Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.730{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00DF-60AE-9302-00000000C501}5856C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061767Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.731{7CDEDE96-00DF-60AE-9302-00000000C501}5856C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061766Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:41.305{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51030-false10.0.1.12-8000- 23542300x800000000000000061765Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.399{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37A161DEE91DC430D536A20ED5823193,SHA256=9F66E436CF4818396C12FCD431AB2B2977613EA807FC3ABA0EC19E017F401997,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038411Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-00DF-60AE-6002-00000000C601}3116C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038410Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038409Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038408Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038407Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038406Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038405Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038404Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038403Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038402Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038401Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-00DF-60AE-6002-00000000C601}3116C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038400Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.423{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-00DF-60AE-6002-00000000C601}3116C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038399Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:43.424{266C2353-00DF-60AE-6002-00000000C601}3116C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038413Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:44.439{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2B34C4D99F9829226DDF5E101F0A18BA,SHA256=3556273FE597E4EFEC36CC228BC3331AF8E47544C49B5DB5DB40AC74FDCD35E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038412Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:44.033{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B899355220072096375E96946450DD29,SHA256=C23F599D4BBB569A7EFF59550DC778FDE6680B29B4D1F0070DBFB91AD9F8F302,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061782Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.860{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=2C93C40E780C65A6BFC468D4F02DB78C,SHA256=335F30D3A5917756AAB15F4B216F9E37565621FD760CD401876E7C7383D53887,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061781Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.860{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=3C583C5ADA2C50338AD4A603F020A9F2,SHA256=323F563ECC6B52386D0EA7D6E510CFB6E7A08E2DC8998285A8945851A1B70184,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061780Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.860{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=7ACE467243B254FACCE3FC7F54D7CF3E,SHA256=3CFC655C016115D030DE1461BF88127D7874EE87C5BFE487449508D588ABD1C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061779Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.860{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=F80E603F53B2D2B4FF12E32A58C53598,SHA256=1A56A6C7814124CDD52AA150155C05D225CB3FB57924DBA21D7CEED2A1E47CF6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061778Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.860{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=FE825CB18C3C234482563E354D44DC53,SHA256=6D2E578B7487AADF5E901B28D7DAC2AA477F746BABDF4CCAEA3FBF001E4FF45C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061777Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.745{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1F94FDC3E1C66C5C9B3480DC41C6167A,SHA256=6848B74D7D262232EF2B199C38B2B90DE13116E78BB46887933B1A85767990EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061776Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.629{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061775Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:44.430{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CEE99C2CD0545783E53D6297795F56B2,SHA256=27706DD2036142CDFE2AA9E819E212AFBC6AAF430230208E37056101AA81C40F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038414Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:45.236{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5328AB348B74D13FD18EB11A1E2733A1,SHA256=B6637CBC3168BCFD797770F611663E2A24F8DABB747E181CD283ADAF207E787B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061795Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00E1-60AE-9402-00000000C501}4568C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061794Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061793Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061792Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061791Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061790Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-00E1-60AE-9402-00000000C501}4568C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061789Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00E1-60AE-9402-00000000C501}4568C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061788Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.860{7CDEDE96-00E1-60AE-9402-00000000C501}4568C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061787Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.083{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51031-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000061786Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:43.083{7CDEDE96-F0E1-60AD-2D00-00000000C501}2484C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51031-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 23542300x800000000000000061785Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.460{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9ED1F5DCA652C0A09B94027A5BB799E2,SHA256=2E2A5C1EC5AC4A6967B8AD5F4CC63B75C2AF5274A34C5FDBBC38E7355FE33C2A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061784Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.229{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061783Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:45.229{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061807Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.878{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A38D9666AFC7A82506EDC2BEA6F00CAA,SHA256=4EFA1E0D79F3FBF7D3AA42433C0EA26F80AADF501D63845AEBA95973CBF3C40B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061806Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.743{7CDEDE96-00E2-60AE-9502-00000000C501}50124700C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061805Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00E2-60AE-9502-00000000C501}5012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061804Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061803Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061802Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061801Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061800Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-00E2-60AE-9502-00000000C501}5012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061799Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.528{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00E2-60AE-9502-00000000C501}5012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061798Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.529{7CDEDE96-00E2-60AE-9502-00000000C501}5012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061797Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.481{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=69EFBD12272863A2D5650DCBD2BB4438,SHA256=3A986C4606373D0CBD7C790F50D9C4586E6597FF9405297D199D835DC4ACDB93,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038415Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:46.252{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03240AB353CE8D98FABF97CD009611B7,SHA256=A95994F6A1452222FB4D39E6A6A0105730E8EA283CB7FA681B14D5C56CC3AA35,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061796Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.098{7CDEDE96-00E1-60AE-9402-00000000C501}45681016C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061817Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.497{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=452848F31C44DDCF541C963F5F108770,SHA256=BBEFF028238953ED562247B12788E86016DFD99829EBDA4186D9FECA6391D76D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038417Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:47.955{266C2353-F0DC-60AD-2300-00000000C601}2112NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038416Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:47.267{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C806AEEAC47F095D8BA02562A541CE5,SHA256=72B62F090073A8A5B1AB693E1C9FADAEC8A228784B4A8597A40816EF9FE575D2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061816Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.343{7CDEDE96-00E3-60AE-9602-00000000C501}37965916C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061815Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00E3-60AE-9602-00000000C501}3796C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061814Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061813Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061812Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061811Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061810Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-00E3-60AE-9602-00000000C501}3796C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061809Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.196{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00E3-60AE-9602-00000000C501}3796C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061808Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:47.197{7CDEDE96-00E3-60AE-9602-00000000C501}3796C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000061828Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:46.317{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51032-false10.0.1.12-8000- 10341000x800000000000000061827Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-00E4-60AE-9702-00000000C501}1096C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061826Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061825Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061824Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061823Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061822Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-00E4-60AE-9702-00000000C501}1096C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061821Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.658{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-00E4-60AE-9702-00000000C501}1096C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061820Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.659{7CDEDE96-00E4-60AE-9702-00000000C501}1096C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061819Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.511{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=540CF137EC91F7BBFFDB5291736DB50F,SHA256=5CEB70ECBD500D20FA060750CAA7B65E9D592DCE1291B9AFDC744043F1C82964,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038419Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:45.284{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50549-false10.0.1.12-8000- 23542300x800000000000000038418Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:48.283{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D58CF9C64E464E77A933CCB621B17C7,SHA256=357E85D99207F3C66316831E81BDA6AE1CB29DB3AFA7B061B1BDDC5D75E55A80,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061818Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:48.211{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=077A1AEB65A2BE13366D47DBB0199128,SHA256=225F4598424A2C928D7DFE09A17C124EEAE8931F45FB592E32C0B3C76DD96616,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061830Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:49.679{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C6A5BEDEBAD6E497B63119ED27132BD7,SHA256=FA0D34407EDABAD031A5D1FA6A3D6D8F7375F031EC953548588F1E907A3DB725,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061829Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:49.526{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF9DD2050E5419971EAEC69EB16BE226,SHA256=16C470798132F1823B1FAB8C5F9A2A4DD4FF4B60015AB7B044909622C7C30DA8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038421Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:47.082{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50550-false10.0.1.12-8089- 23542300x800000000000000038420Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:49.283{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=493903B6C21FB04E7FD81B8A586070CA,SHA256=DC8EEAEB5F208FA49E7C93281130E7214B2CCCF80A9E8D21A6FBF45BDA20D189,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061831Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:50.541{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C910830E79F0C27D675BD18BFA100307,SHA256=6F4575E96DEF9553DAA57F76B40DE1790870F249FFF4188305DC4B0B00552A1E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038422Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:50.518{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=58D27F82D502EEEF09D641D664B10FCD,SHA256=B44C3D09C631C59894831536C163014D33F6A7F3D9667CD5D935E4B0D836A1C6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061832Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:51.556{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=672AB21EFA04F309BC03A219D2B54DFA,SHA256=72E5E23E753CCFF14377229C83AE3BDEDC3FC51BAE5678F18C73D53D485AD371,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038423Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:51.565{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC25016BB00E91D4D5C7376238786A5E,SHA256=FB8283B1DEF0CFEE28DF6A6EECB1D3C9199F051D53E7AC18EB492DA08165A6B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061833Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:52.574{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C05E791E42017F9053783CB39C87C30A,SHA256=4E30F173E94B2C5D6A25C42B9EF579A2F802907D481506F06005DE1759D070AA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038425Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:52.580{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9B8B0CDE2EC9A6CB07F3B10B3D333BF6,SHA256=D5EB966B47A76C0E86468F007E613B773FFACB43E5EC690AFD3710B7A67802FC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038424Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:50.316{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50551-false10.0.1.12-8000- 23542300x800000000000000038426Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:53.612{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A258D03CDB196F2428FE2FF9849B327,SHA256=C1A948B89B9EE0212B0389427496A23001CAA0D17A28379047479752623D229C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061834Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:53.608{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26EC8EE603DAA4ABA32715CA5B9313D2,SHA256=EBF1CB1A502FC4CCFFD61F848E15A889F89025BD7F6961611083BF6FC7980AFC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038427Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:54.627{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3533D3479D12E49926DB0695E9E5AE51,SHA256=2D51C7A902EB3255164424F59F9AB6BD6CCA2B9341865B407D8BEC5EB3A2D5FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061835Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:54.641{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1294208634B8B71FC3FF644445F25A74,SHA256=5DFEE824EB253CC5B34DDA618B7B72B0F5CB2AC15195BDA8595CF8AE7A21F237,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038428Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:55.659{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF0B2C4E589ED41CF21053FEB508C947,SHA256=1B643BD2B94DDF58EDC6B681A4BCAB18BF88120AB787FA7AC93D2B86970C7F34,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061837Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:55.655{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD6C395AD97CF4BE3B40A20886B698A8,SHA256=09179472B6820819EA626A37805377A82CBAF90A6AA2C81A165375F66C5C729E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061836Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:52.345{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51033-false10.0.1.12-8000- 23542300x800000000000000038429Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:56.706{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=40FF306C484638A6F52DFAF66B01E22C,SHA256=AB53EBF077110EB0E43CF7B095E55DAC910BC8E6972E63FEBA359EA7E2A2DF0E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061838Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:56.658{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=13FD3D96D3AD70B14EF5CE7952976B2A,SHA256=19303C4B08851AE968DEB803630EC1BAB7608A8412B35E4AFF839687C452F4B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038431Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:57.753{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D38994DF0D93D3B0A49E28ACF8D8486,SHA256=B28C836CB697747B37B6D4A9F7C4EA986E3F6C00B5562CB31473F8B02C6A2113,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061839Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:57.675{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=54632A446675277564EEF4AAF4883BDA,SHA256=7ADE8DACCC5B0AF315CADFC74D5946CF7057DB7194A02619F639AFB3AD672F24,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038430Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:55.378{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50552-false10.0.1.12-8000- 23542300x800000000000000038432Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:58.768{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED081111E5F6BB4770A243844F48F37D,SHA256=6040EE66D5BFDD6DFF1C54444C0B6C4A2ED67AD1B7D6BD1DE849C1DFBD6B2513,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061840Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:58.694{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EEB9F59F83FCD1E3EEE53169B0950348,SHA256=0B7AC0845A8BD9CE0B93523B6480DA3E8B5499ADF83E2B2F3B95694E7141099B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038433Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:03:59.800{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EAD9873F4AB826E02E9EDBE9857E70DE,SHA256=BE325140BECBDC726803079CBA5BFE1B609E88606F747384F4F2DAC42F83C30C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061841Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:59.709{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE372A046BF2D591B75258ABB3FB8979,SHA256=2DD7D284B935398BB76041772CC83D90A0EBAF84DDCAD47DA89793047DAF630E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038434Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:00.847{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=43131C7307987961C404926EA2A32E70,SHA256=221AD598BEEB6592A3672C9152613ADCCA5BA8202DD186502C35D04809120DCB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061842Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:00.725{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8CD08FFF21427F230003071878DB9676,SHA256=FFCE3D4B35C3253D0739BBCF76CC47CB7993D02FEFDDBCAA95B74FE7A90F4A0B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061844Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:01.777{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=17A2EAA3EF1394884F1A7D304D25AC25,SHA256=36399ED02F8D3241B23265042F57C67ACA72D154E0FAC7C5A5185EDAEF10FB14,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061843Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:03:58.330{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51034-false10.0.1.12-8000- 23542300x800000000000000061845Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:02.794{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E38EA610A7B79198F80635194FCE0CE,SHA256=29EA50AC40252BE822210B988BDAB5DF65D519CE3D04FF899F59AFA87EC13CDC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038435Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:02.081{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=721C4ADA667CCCDE2477235BE7B6EC39,SHA256=4B2E0E33BE3B07138064D09F6928C94D839EBE89361DDB03FA3F7F53D18A7B62,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061846Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:03.824{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=78881B9B91830598A086CCCD0AB1FA1D,SHA256=676C9004C9FB396356344454CB6039D519B0101E61B23E25B6FF804231F7574F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038437Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:01.285{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50553-false10.0.1.12-8000- 23542300x800000000000000038436Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:03.113{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=60E0C62370151C4393C71E9548DA9BB3,SHA256=F4AAEA4FBA2344CDDC437DF6E979AF4D4690EFE44772342B9D2A1C8FBBB1721D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061847Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:04.854{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=391FF36D69F7A2EFDD1116BA9D095353,SHA256=CC3C05D5C2B6125C2D4DE01832CF9AC195B415D34CF989702037A1F09C907B9D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038438Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:04.176{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8FCA1B9FD9E39FE2B7D15DA11BD8749A,SHA256=5F23FF8235E97D6F8033BA18E7986EAC9AFC5803735E273AFF2A0A6BD6EAA333,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061848Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:05.875{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2CBE333C3DFBE035045CC9FA320EA439,SHA256=072A2653B45D973561B81D345A61A076015256A58797D95009D7D569A1AE5702,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038439Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:05.207{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C87B3DFFF5B7DF99156BB03B2BAA99F,SHA256=6D541886B82DEBB331BCA94B8D8AAFD24CEA0061E355AAD3094CC18CAAEB3A1A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061850Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:06.891{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F771C301DEE19AF7A5C616D351B6EE1,SHA256=86FEFA210AF99B2F7C99E44F4845CD769E967BCCE707E81CFEEA4EF90AFF58AC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038440Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:06.223{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5A898449F42E1D3952871804BBB0DC9,SHA256=FDD98868393C5D5E974B04616D27E192453989114B03F97A5E9B65516609DA95,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061849Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:04.190{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51035-false10.0.1.12-8000- 23542300x800000000000000061851Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:07.922{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=17D903DEFBB22671DA8D0D80829355E3,SHA256=29442FF9638BA83BAAE868CE36AD64EDD58C9F9AD30E75C187968B8C300372CB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038441Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:07.254{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E562EC5E9169F11BF7D2C7911D978B48,SHA256=B7E6EF22111DBAA76765784A9C821E24A93992AF31AD87A490C5F89A4A5FC57F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061852Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:08.952{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36FE78D2A3815023F06BA90654C88259,SHA256=DCE9184C77562183D14EA52105FC8E8EF4895CE178700F044E3A851157B301A4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038442Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:08.473{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=532AE1C1805437B0AB49B17D8C63019E,SHA256=1C88C8F909D19F9D4D316854FC6A143D3472DD18D7DC9C51366EFB6AA80B37A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061853Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:09.970{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4DDB2E4CC1CDD8E7A766DFE1E2232486,SHA256=43DAB1732DA440C59282A51A9E44DB2E81E1AE71097EE9761D29D0543024F570,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038443Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:09.536{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B99C4AAE9CEB7276908E67AA2384C65E,SHA256=821F5ECBB40F35746D2495BFBFAEAFEFD6304C3F4F128B7EE6A19334042B8041,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061859Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.987{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4013DE72E0E84BBA1C27AA94E51187C7,SHA256=71048BCF37AEFAFF8BAF61725DD72512A60161A5673CB6D243EB59EC4685B4A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038445Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:10.567{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D3CC2024C5FEB1F0E54DE34E2A9F43F8,SHA256=0DF93C48259D89DC15ABC06BE9C1138D5CA066A510A9E894447F6D1AD267FC24,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061858Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.735{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=198A3DE33520CB862EFC1F92D01C8B40,SHA256=298585C6E6E03CB6CF5D30741CA19A6542ACB0C8A2E86882CA91BDF4439DFD42,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061857Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.735{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=77B14EB1A465CF52BBE68EF94D7DA595,SHA256=C8FDFE26E1FD864452A248D06C0350047F13434ADA86E55A3A730C0AB6895299,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061856Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.735{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=E6F5D0F49695AF38AB84A9EF3A551F41,SHA256=7FD53991BAF2DE43FF7461BB04CA6DF3EFF3B8F37E98F8AC2AE0635920B2212C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061855Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.735{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=A967045D76C1E81B3ED1C2EA2D065A2E,SHA256=8FF33E05B298A4AAC1F354FAFBF70E70194F91A6E8A7321A20674B229265AC23,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061854Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.735{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\datareporting\glean\db\data.safe.binMD5=D3D386FBA03B5F5D2626B050F53A71F8,SHA256=5BE02171161D7ED1620F782DD8F8AD1D7F4178F77AA4B1023FCF25AC5EBC90C7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038444Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:07.222{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50554-false10.0.1.12-8000- 23542300x800000000000000061860Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:11.988{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E811F6902DC6ACEAF95527E30855F4C7,SHA256=D43517D09AC9DF208C8EB1766A4A1A5A131EF021C1F80E33C5488D2E0F62B6EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038446Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:11.583{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3E35D00B25264B56678B09AD19702D12,SHA256=CC336A2CC5E90F82FDB205E706B8BB726B603828BFE80B8EFE1D181C07B9DF66,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038447Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:12.598{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2151775846C8045C0C9AF99888EE1BD4,SHA256=DC7854EF49DAA99896EA290D740A3277561C2E8DDD6BA73A83ACA1DD93CB219B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061861Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:10.171{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51036-false10.0.1.12-8000- 23542300x800000000000000038448Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:13.614{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=763E8AE49BCB0242896F83F5346EBF14,SHA256=E502247AC85761EB0DE80076A7CD3AF752341641BA395DCCA0711EAD33D4C28E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061862Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:13.003{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=19BC53C3DEE300735762247C631BFD3E,SHA256=EEF8F6EB9FB666CA98A472936710899258A3E50E5ADC8E82A77DC4DA61D27547,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038449Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:14.630{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=07DD8A3BDC68C0702AB2A65423026DDE,SHA256=85132CBC5B86C349C3BC71D191B53AF0326265BC6FF7014EE1C2BA76B884E52A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061864Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:14.749{7CDEDE96-F0D1-60AD-1100-00000000C501}388NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=03CA1666DC9FAF285FADC3AFD35CD878,SHA256=73A40395A05045D0D68D9023F3A7524523C67514FCD27F1A0CBE6817C26FC113,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061863Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:14.018{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39950F9AED401905A94E9FC86EC0B265,SHA256=C1F991C7743684B1B485614138533BBC8B4B571423EFA8412A5CF7F74C73CF6D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038451Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:15.645{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=545F22D0C0241C6AAAA43F1C3538479B,SHA256=FED058E5C048B798AFBE889AF8F09508F481169ECD4EC1B8DA601F3B7EB16F0F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061865Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:15.033{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=96656C2E0542D896F0A39D116D4A1EC5,SHA256=24D78DBC29C6976DA5EEBB40EBB94AA1C69F891C5989FCEFD3E78400AFCB13F0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038450Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:12.332{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50555-false10.0.1.12-8000- 23542300x800000000000000038452Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:16.661{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EAB5ECE8EF5CABD24142201453748C57,SHA256=D6C6A663FC093C581DC391A40E5D035B1E9D05241A57387183AAFCC0BE366988,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061866Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:16.048{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9DACFB4194755CADC31D377EC7FDDAF6,SHA256=925D727A36635479100C2F132205FAF321CA82790BB97E28F2FDC5748F3757E5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038453Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:17.677{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E641E32DB8B58AC0066FD635538A9F18,SHA256=EA8747D62496E482C12B32FFC4780C75C502BDA5097D85B4E74DF2E4C9CAD408,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061868Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:15.321{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51037-false10.0.1.12-8000- 23542300x800000000000000061867Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:17.064{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEB2A5FD3143455DEE103811EC14A07A,SHA256=B6CCD03B2E1A4D5DC1EB03946A92931FA5C3AD0B6EF24A04F1E50FA3FEBB8D64,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038454Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:18.692{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=483EE632F4ABF6DFC280737149EDDFCE,SHA256=903DAAFCBD3550EECBCC9B8238BAAAC27A5EB6F8EF0076D890DB789B02D279D7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061869Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:18.165{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26BFA9AF3B05BAC9E05E655428CD09C6,SHA256=F724E6C76ADD32062C131BB8341A3883676339902864A1A37ECB77CD77AE0136,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038455Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:19.708{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE5690368BC5C8EACBCC742B1804D2FC,SHA256=AC74E9554F267C86E8EBE09157B4D7A4B8143C034384F118951F9264C2EDE2E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061870Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:19.183{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EBAE151ED048B651AC479588ADD8D412,SHA256=A90C3D9C8D46575AD324F56CE7784C3739000D8A8BBC84D94B2F105385D2A735,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038457Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:20.724{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EDFBECEB176F39422172C908A59B891,SHA256=77FD97DF60203EA872C6B127549A1868A75DAB7F5769469468207EA2ED5832F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061871Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:20.198{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDA5D526EB737BFB866331892C74CFE0,SHA256=1F86A9CE8EF8D48E5C3700C4DA41ECA34B5E59A7744FE23778A9C9EE0A9ADD94,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038456Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:18.206{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50556-false10.0.1.12-8000- 23542300x800000000000000038458Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:21.739{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=803930944C87E110FA11C5E851420BCF,SHA256=29C9EE293EB5B3494D028A6E59CB04FE2E3823C7D65193A69860AACB0227ADED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061872Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:21.199{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A51F5A3653DFC4C94780CA110FEDD1E3,SHA256=9177764F239BDA4B2F76F3FAA98B8B95E57ABFD26AE3AEB31E93053A8BEA92A4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038459Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:22.742{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A5A39758BF5621FFD023923049CD0646,SHA256=96B3F5D20154580403C1AB53F68DD3F3566E1745B3777A0935DFE99258E89AFD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061873Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:22.214{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=209249475E9605E6B7F26EF5084A11AB,SHA256=8ABAAE83C87E6AF33A6EE7E37B5D9B65F342121F6D217B106C344934B20E8EF8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038460Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:23.743{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8CE144B5491E9174FE2FF9804B6496BF,SHA256=3FDBEC78017C958CBFA1D3FF4902F57BCE7DB060C9BDABB9E0E6B164E1E8DA98,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061875Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:21.204{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51038-false10.0.1.12-8000- 23542300x800000000000000061874Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:23.298{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EEFF31A3079130C509FAAA153696DE5,SHA256=536172392FE6799085764CF1925B55C9D472F488464C7B42EEC73E3D7346A0C1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038462Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:24.898{266C2353-F0DB-60AD-1000-00000000C601}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=52F2913386454D4FF25CB72A1FD2AA59,SHA256=BEF14332CA1A4BDC3252D390CE53A5360C000D4FBB1C1666BBEB40C0F8817DAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038461Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:24.758{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8AD1C8CB9EB0B44B0BA5E55CD5389735,SHA256=99A446710D3BECC87FEA128A7CDD2A917FA95E78C971EEA75DAA59EAC775B145,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061876Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:24.313{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E817AB065D34573F43B12747C89B8D74,SHA256=20269E736DB38DA87854874FAE6E272D791E99F33A4DBCA26F58699636EE9E66,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038463Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:25.773{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF78CB2CE285E1B3068888B44831507F,SHA256=41D9A7D301153A2F846637B123D882B718AC27D453BAF3B9E9E876D15C6B49B0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061877Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:25.329{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=392C6FD4484DFE350D11A5D2D9401FE5,SHA256=D578D7FF8BAC746A92458C744E64063C81278621B1DF593E4DAD4559E540BFF8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038464Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:26.789{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5213695ADF10C164028AC9DDA40CB08B,SHA256=63610D3DE679E8BF323D916D1D40DC673E25A11D20F13AFDB12723007309B39A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061879Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:24.336{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60408- 23542300x800000000000000061878Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:26.345{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24B8264FA464EADF7102618241FD4939,SHA256=0829464DD40E361A4D5605E3C407FD89BAA1AE5F4D647608436E5591AB34CD6F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038466Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:27.805{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7A56E7B699EE6C5C1913D30330515220,SHA256=F302EB755FA1364B7FB87014A8EB2723C860A471C7E463416753E0EF6243FAEC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061881Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:24.337{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local60271- 23542300x800000000000000061880Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:27.363{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4847F53A69866896FF5733DBF5C9AC0E,SHA256=D1D9B68980EE99C8AD87664C3F7142C891D8AAB41F91E001D3CBA4ED70364A82,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038465Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:24.240{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50557-false10.0.1.12-8000- 23542300x800000000000000038467Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:28.820{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE490E16E5F7E6E13C4FC3CF06A58EDF,SHA256=364A1BD30FE32C2BB2E866ED14D0ED9ECEF631CF56CF5A7959DB0D74BE5CC756,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061883Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:26.302{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51039-false10.0.1.12-8000- 23542300x800000000000000061882Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:28.397{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BF54BA038298E0FBE52493CF64C2A43,SHA256=0E728B150FF36F2FC1A4CBC1AF4C2056337C60D6405894277F6E96E09607C143,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038468Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:29.836{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=00E03E0292E47B21CBACD8B11AB82C22,SHA256=2986F47E9F15BBA517FDD97D899F8A4C7F25C59669B7699ED6D1838D0CD839A8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061885Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:29.680{7CDEDE96-F0E1-60AD-3000-00000000C501}2240NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061884Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:29.411{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=372CA6A586FDC8BB501F12466564B042,SHA256=E4E61E1A7C1D6B5F03CC9A832543E6F8CB8EEF3DE93F54AA11A4A37C77959E5D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038469Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:30.836{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D6377CF05FA3397C2453DF1166304BDF,SHA256=3D2E78486806F6C5E9EFBB016A4CD315E70A1CF8D7A571981350380C5867ABAC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061886Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:30.460{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AA23DE601FDC26F376149BFDEE95800E,SHA256=932CD92B48D17D1B034DC391DF6C15B6E2B400334EFCBCBB841D071014C328C7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038471Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:31.852{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8AEA8E05A154DDA6F905FC67DB843017,SHA256=183A69367D76A6AB3913583F7432519CB154F988EA59256A5651D914F6B61A13,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061888Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:28.801{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51040-false10.0.1.12-8089- 23542300x800000000000000061887Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:31.478{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A15EA3DA752D16883E0BCCB76857A6FF,SHA256=29B5EE0B16984348C627950DD2798535E4B736229C33B2E76359BC7B87D53412,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038470Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:29.365{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50558-false10.0.1.12-8000- 23542300x800000000000000038472Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:32.868{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=584391A84C79AAC84F256BA0D87C039A,SHA256=B5768AFCA24C3B4A0C88D6A0C17D9703776ECCF338CF285A3EB109C0FC40E4B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061889Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:32.495{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EEDC78F7A75452E6E95F31E4454752A6,SHA256=69DB2AE6F2CFBD101D8AF7B0DE9852DBB51720E8DBDEC552E5090550BB7AA097,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038473Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:33.883{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03F9550A2354BFAD91041683C44862BF,SHA256=B97B675A570FC5ED73917924656630673ED277A859B0E28BD154A57403519337,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061890Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:33.495{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD005E88C02E2A1A599C622A518A2E4E,SHA256=D585D5941E683E110D26B0B64FE69C0AB2E0566937CE3DEA75A78E2E78859131,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038474Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:34.885{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E8B6401BB55D142172B730CD51E05E4,SHA256=4260A1E37EDF106CE1E87D2EC25902BF1E38277C1D2A4ECF67E61E8EF3006C2C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061891Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:34.497{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=572023AB6A40C015FB5AD9A464826C89,SHA256=C9CC7A11708ED09665353B9EC50AF5745D65D6D9B0547D747F13642BFA75D295,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038475Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:35.898{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5D4F90200E7056035DBB0D7CFEC939C1,SHA256=A85DF7374917252B4586D503CA1CEB20A03D77E48BD394572CCEE0A8186E4E72,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061893Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:35.513{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7ECEB7AA901911267A0FEDFEE5C68AC5,SHA256=8F1A1CBCB950031695EEF5A9C8AD0737894EA0838B28B8CF8917CCF42C85DA17,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061892Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:32.178{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51041-false10.0.1.12-8000- 23542300x800000000000000061894Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:36.528{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E301CC53B8387DB9BAF78226D75A49A,SHA256=FE1A9B70AF03E22A3D5343F33D802B906880A3AF5D27D17FEAB4F8D710FAA3DB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038502Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.885{266C2353-0114-60AE-6202-00000000C601}39802744C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038501Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0114-60AE-6202-00000000C601}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038500Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038499Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038498Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038497Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038496Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038495Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038494Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038493Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038492Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038491Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0114-60AE-6202-00000000C601}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038490Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.635{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0114-60AE-6202-00000000C601}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038489Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.636{266C2353-0114-60AE-6202-00000000C601}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038488Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0114-60AE-6102-00000000C601}2460C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038487Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038486Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038485Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038484Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038483Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038482Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038481Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038480Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038479Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038478Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0114-60AE-6102-00000000C601}2460C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038477Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.135{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0114-60AE-6102-00000000C601}2460C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038476Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:36.136{266C2353-0114-60AE-6102-00000000C601}2460C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061895Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:37.567{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3496834366B16D6C4F0A27B3E5F4D40D,SHA256=D0A1ABDF15E49F021620750A0A779F19FE23F8C3F2BF1896F087E4BCA4DF02D5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038519Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:35.210{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50559-false10.0.1.12-8000- 23542300x800000000000000038518Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.432{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3273AB64D7496106420CBC1B4EEABA96,SHA256=34E96BD6EB64DC1EAE84E067BF24A1A7C0062E6E1B94E7C29EA6746785ED3347,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038517Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.432{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE29FC416A2856F41E101B0FF51C78C3,SHA256=F89B2A867A96BF3ADEF60E1496F041C321374ED97E194002B558748EB72C9E5E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038516Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.432{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=390C4F84D79F718072C8B7F6C257DB4C,SHA256=14D8BCE838F1A339CC68A1F2E6A3A3CA2C91EB75AB10732D9E09AEE9926115AC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038515Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0115-60AE-6302-00000000C601}424C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038514Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038513Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038512Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038511Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038510Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038509Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038508Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038507Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038506Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038505Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0115-60AE-6302-00000000C601}424C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038504Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.135{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0115-60AE-6302-00000000C601}424C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038503Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:37.136{266C2353-0115-60AE-6302-00000000C601}424C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000061899Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.966{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061898Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.862{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000061897Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.862{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 23542300x800000000000000061896Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.598{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B616F28BE6C399E8CAB11B436F7B58CE,SHA256=FF7CA7EF896A6CEC19490F7C44A0114159034404082696AFF94FA3AFF2FD715C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038520Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:38.182{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F81ACC476F38171913D75D67FDB21468,SHA256=2BFFD5D3A00AFD8A688C5AC79010C682A2AE484339C4F2546B6DE29FA32594D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061909Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.604{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6AB2D147B6CA6E4DB1D2F30934743BE6,SHA256=0A83B4861C9C79C993D2B3F1289B6658F3760816AC69EDA8171019398099EBEF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038535Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.979{266C2353-0117-60AE-6402-00000000C601}3148368C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038534Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0117-60AE-6402-00000000C601}3148C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038533Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038532Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038531Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038530Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038529Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038528Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038527Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038526Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038525Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038524Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0117-60AE-6402-00000000C601}3148C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038523Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.713{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0117-60AE-6402-00000000C601}3148C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038522Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.715{266C2353-0117-60AE-6402-00000000C601}3148C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038521Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:39.323{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EBB518D5D602E79A4D90E2D81B2253F,SHA256=A3E8AF47B223112CAFB946E064F157DD0512FFFCE96E2ADBDA08C307D1D5BCB4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061908Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.519{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061907Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.488{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061906Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.419{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061905Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.404{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061904Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.368{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061903Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.352{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061902Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.088{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061901Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.035{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061900Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:39.003{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061914Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:40.606{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EBBABAC06470C2FB31CB2BC4AE3039B,SHA256=A194833FCAB2BDE588ADAA9D781EEF733B681B60395A62CD0C8F168DC06876CF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038564Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0118-60AE-6602-00000000C601}1092C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038563Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038562Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038561Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038560Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038559Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038558Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038557Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038556Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038555Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038554Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0118-60AE-6602-00000000C601}1092C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038553Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0118-60AE-6602-00000000C601}1092C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038552Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.857{266C2353-0118-60AE-6602-00000000C601}1092C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038551Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=775FAC1FB731F8D0991EDE908B550E63,SHA256=8914A4FE5D6AABC8B318D2F35B8803B13D032F51EF909D88AE2904486DAC2611,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038550Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.854{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3273AB64D7496106420CBC1B4EEABA96,SHA256=34E96BD6EB64DC1EAE84E067BF24A1A7C0062E6E1B94E7C29EA6746785ED3347,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038549Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.401{266C2353-0118-60AE-6502-00000000C601}6843620C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000061913Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.509{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63807- 354300x800000000000000061912Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.449{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51472- 354300x800000000000000061911Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.443{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local51043-false185.199.111.154cdn-185-199-111-154.github.com443https 354300x800000000000000061910Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:37.266{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51042-false10.0.1.12-8000- 10341000x800000000000000038548Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0118-60AE-6502-00000000C601}684C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038547Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038546Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038545Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038544Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038543Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038542Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038541Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038540Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038539Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038538Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0118-60AE-6502-00000000C601}684C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038537Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.213{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0118-60AE-6502-00000000C601}684C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038536Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:40.214{266C2353-0118-60AE-6502-00000000C601}684C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038567Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:41.870{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FB6916D280BD3792025783CDCE3D99B7,SHA256=E2DF8AC60476EFF62EFB61C5E35279648856E4454E1170E5566ACA6B944AB52E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038566Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:41.510{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3CEC03D7F74938C6CD2DC21487C5C832,SHA256=C6BDC59698703229492FF279DDF0A2F1C2C5F99C538ACD5E6153C4612C95B7AA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061929Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.638{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DACD3E6C5EC5DC698C5F896687032AC3,SHA256=8331D96A92C7DEF95B91071E3C10F1F1FFA4B64C699B7AF7CDC63B2CB6AF8176,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061928Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.606{7CDEDE96-0119-60AE-9802-00000000C501}10164688C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061927Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0119-60AE-9802-00000000C501}1016C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061926Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061925Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061924Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061923Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061922Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0119-60AE-9802-00000000C501}1016C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061921Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.406{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0119-60AE-9802-00000000C501}1016C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061920Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.407{7CDEDE96-0119-60AE-9802-00000000C501}1016C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 22542200x800000000000000061919Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.522{7CDEDE96-003C-60AE-7C02-00000000C501}4140api.github.com0140.82.121.6;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061918Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.522{7CDEDE96-003C-60AE-7C02-00000000C501}4140api.github.com0::ffff:140.82.121.6;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061917Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.461{7CDEDE96-003C-60AE-7C02-00000000C501}4140analytics-collector-28944298.us-east-1.elb.amazonaws.com03.223.228.231;54.167.199.174;52.2.180.220;52.54.72.115;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061916Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.460{7CDEDE96-003C-60AE-7C02-00000000C501}4140collector.githubapp.com0type: 5 analytics-collector-28944298.us-east-1.elb.amazonaws.com;52.54.72.115;3.223.228.231;54.167.199.174;52.2.180.220;C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000061915Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.460{7CDEDE96-003C-60AE-7C02-00000000C501}4140collector.githubapp.com0type: 5 analytics-collector-28944298.us-east-1.elb.amazonaws.com;::ffff:52.54.72.115;::ffff:3.223.228.231;::ffff:54.167.199.174;::ffff:52.2.180.220;C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000038565Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:41.136{266C2353-0118-60AE-6602-00000000C601}10923544C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038568Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:42.748{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C80C93B729BA0B9E2E72C1962B368F2,SHA256=2B71FB05382F99A305CBC13162F3B533CF744424A0EBF44B424C4E24453588CB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061942Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.674{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=20E5A0E6720133072BF111E3D27A7206,SHA256=C398DC2063C463AE712C5E2FE21267D7538974EC804398D2CF655A0C7C190856,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061941Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.474{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=061B32497A00D86A1D3BB0893E203764,SHA256=4D2C37885D576FE7317A876456B8ADAFB21BFAAA11C7F872038693F4063B068A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061940Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.472{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6D34835957D501A694B63FE00675F8D6,SHA256=09E690245C032F8D545ED5606139541E0CF682EE96CCF8E6B487B315AD95F5BD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061939Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.542{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local51044-false52.54.72.115ec2-52-54-72-115.compute-1.amazonaws.com443https 354300x800000000000000061938Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:38.512{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local51045-false140.82.121.6lb-140-82-121-6-fra.github.com443https 10341000x800000000000000061937Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.073{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-011A-60AE-9902-00000000C501}5996C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061936Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061935Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061934Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.070{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-011A-60AE-9902-00000000C501}5996C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061933Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061932Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.070{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061931Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.069{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-011A-60AE-9902-00000000C501}5996C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061930Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.069{7CDEDE96-011A-60AE-9902-00000000C501}5996C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000061951Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.757{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061950Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.757{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061949Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.739{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-011B-60AE-9A02-00000000C501}5588C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061948Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.739{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-011B-60AE-9A02-00000000C501}5588C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061947Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.739{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061946Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.739{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061945Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.739{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-011B-60AE-9A02-00000000C501}5588C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061944Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.752{7CDEDE96-011B-60AE-9A02-00000000C501}5588C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061943Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.693{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18DC5DFEE36A12AF0E07DE10D5FADE8E,SHA256=D12BDD2F053DEF21FB9CD17CEB08B6A06C185F43CF56C431D81BE4679DE88A3B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038583Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:41.163{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50560-false10.0.1.12-8000- 23542300x800000000000000038582Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.764{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=94DF5D605346196EDF62B825933D55B0,SHA256=B331A586EAEA04F1A32BD1E21BA3AD520AD3990E4D36609FFC7CAE299C41E5DD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038581Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-011B-60AE-6702-00000000C601}3076C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038580Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038579Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038578Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038577Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038576Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038575Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038574Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038573Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038572Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038571Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-011B-60AE-6702-00000000C601}3076C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038570Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.436{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-011B-60AE-6702-00000000C601}3076C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038569Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:43.437{266C2353-011B-60AE-6702-00000000C601}3076C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061955Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:44.760{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=061B32497A00D86A1D3BB0893E203764,SHA256=4D2C37885D576FE7317A876456B8ADAFB21BFAAA11C7F872038693F4063B068A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061954Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:44.698{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06B73F795982F03B1B0D7B2BE547568D,SHA256=359DA1313D173B02E7B1DBDA595E0A2BC03FFB34D531494FD64B33C9B1219787,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038585Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:44.795{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0440BF078CE433C94E093D2E996F6D12,SHA256=7AA66D7E27BAAB06D77EF94922CD054E8DBAAC3C36A112BCA84A3C1164657C32,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061953Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.157{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57427- 354300x800000000000000061952Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:41.157{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51298- 23542300x800000000000000038584Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:44.452{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=68A6730620C33891CF5D764E610AF154,SHA256=2FE49527234EFEC84BE5C80AA67754759FBAEF6294DD5573A8B314C6ACCA56CB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061968Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.883{7CDEDE96-011D-60AE-9B02-00000000C501}23482356C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061967Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-011D-60AE-9B02-00000000C501}2348C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000061966Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B07AD537D05A6E777C5FA8FC3E054B6D,SHA256=DF524B1A16E94F0C65F36F4EB79798319C7B2BD54D80FA52F4B99D4DF1EC5972,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061965Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-011D-60AE-9B02-00000000C501}2348C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061964Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061963Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061962Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061961Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061960Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-011D-60AE-9B02-00000000C501}2348C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061959Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:45.714{7CDEDE96-011D-60AE-9B02-00000000C501}2348C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038586Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:45.827{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AECC3ADB7214010FC2BB001C9A2AA838,SHA256=EEC7EA6715721DF0FBFCD57C27D80F8355BAD415D7A243F99D4440CB35F2F9B3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000061958Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.095{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51047-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000061957Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:43.095{7CDEDE96-F0E1-60AD-2D00-00000000C501}2484C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51047-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000061956Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:42.309{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51046-false10.0.1.12-8000- 23542300x800000000000000038587Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:46.858{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=966B460AA22E57DA8C85944AFDEA6C26,SHA256=0EDEFCEB832BD0BDA06748526416470104B3660B0B14E6ABBF470CBFD548762D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061987Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.932{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9DF596C1DE04EDF089B74B83F611884F,SHA256=8A2D5825973E71DB6DF043092D27B4FEAC83AA2DCE6DCF52DF0E857B2A0F1984,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061986Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-011E-60AE-9D02-00000000C501}6076C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061985Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061984Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061983Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061982Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061981Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-011E-60AE-9D02-00000000C501}6076C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061980Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-011E-60AE-9D02-00000000C501}6076C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061979Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.901{7CDEDE96-011E-60AE-9D02-00000000C501}6076C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000061978Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.730{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4E591894D87BAA585688E034760F7F2,SHA256=85FDD217E8DAFBD1360CEC35C70BE85716302A0A3AFF5241EF1F71BDB7C27C59,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061977Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.683{7CDEDE96-011E-60AE-9C02-00000000C501}20525976C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061976Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061975Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061974Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061973Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061972Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-011E-60AE-9C02-00000000C501}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061971Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-011E-60AE-9C02-00000000C501}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061970Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.398{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-011E-60AE-9C02-00000000C501}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061969Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:46.399{7CDEDE96-011E-60AE-9C02-00000000C501}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038589Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:47.983{266C2353-F0DC-60AD-2300-00000000C601}2112NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038588Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:47.889{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8623BD6A3EAC3D89212F7CC3CF08D9CF,SHA256=573B168CEBE256656AD1806A76A7C982E0ED1A6425BC7E9EA19E39C257306A49,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061989Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:47.732{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6ED7667FEB12EE5396C4494163903FCA,SHA256=10CF0029094D13A2ADED3DCC1778BE7234EB30D13349021A90C623E4D415D250,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061988Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:47.116{7CDEDE96-011E-60AE-9D02-00000000C501}60763836C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038590Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:48.921{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C9BB3C2B8B41B62E18CC5F10A5226EB,SHA256=59EFBE71FF48764FD313AA0958BF885F0FD86EB3265068FC56DE2A451BCED75C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000061998Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.763{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB551885FBCBE2F27A96556E98DEC14C,SHA256=EFF80A81EDA7A191C8F488188A21FD5E67F2EDE647958E70188D3C4486A9311A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000061997Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0120-60AE-9E02-00000000C501}5740C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061996Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061995Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061994Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061993Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000061992Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0120-60AE-9E02-00000000C501}5740C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000061991Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.663{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0120-60AE-9E02-00000000C501}5740C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000061990Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.664{7CDEDE96-0120-60AE-9E02-00000000C501}5740C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038592Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:49.952{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09550F8AF70BFE637C2AB311C838EB03,SHA256=20386E4AD3D57FC910194C6EFCC67243260E50772358FB974B74C4E4752216D2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062004Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:49.849{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000062003Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:49.849{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 23542300x800000000000000062002Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:49.786{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=470DC897BE6EAE156B65E7ECFA21B606,SHA256=43CBA9CF693F727E9459DED23D6D5D9FFB95FDAC536E67044CB3F2C08B177E5B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038591Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:46.307{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50561-false10.0.1.12-8000- 10341000x800000000000000062001Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:49.749{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062000Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:49.749{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 23542300x800000000000000061999Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:49.665{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EA7F5D554F8B1698FA3B3A453A6E6C46,SHA256=88BD358D4C3A93AA5968C9E9EB67BA5B36F4529D0CE2B7032C40C6C07824DF27,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062008Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:50.802{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AEA4B285E048AF9256D09FB9B71F31D4,SHA256=A1E33F3BC3919B940629511D27A1070D801E972B98B48DE0267F52133ED4DB04,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038593Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:47.104{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50562-false10.0.1.12-8089- 10341000x800000000000000062007Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:50.364{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062006Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:50.364{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 354300x800000000000000062005Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:48.183{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51048-false10.0.1.12-8000- 23542300x800000000000000062009Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:51.817{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0F914AC5A670C855D72828E933BE694,SHA256=05E258AF225EE6C2D810E87A68DFB302AE4E9A0AD94F2DD04F6E9C9811128DFE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038594Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:51.061{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1374AC3179291D46BF1A8DA0A501A09,SHA256=666B640682FFD67F9F17E70DBFEF0FACA23708C173D46E2EEC5B9A58B9D1D386,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062012Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:52.963{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062011Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:52.963{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 23542300x800000000000000062010Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:52.832{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=837015C7969785FFB98FB0AC8F1FEAF3,SHA256=AF59B2B80F6F558A259E114E369A8BCE03A304EF5FA6D5287B7BB73904D20FD6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038595Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:52.077{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDEBE4C33559E62176A34F40CBFB2F82,SHA256=C5F39E4D976A2EAC11DAE4505037691D5475C8251E97641745C47C740E448BBA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062029Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.947{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062028Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.901{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062027Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.848{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5ACB88C5BFFB3275BCA65CEFE228091,SHA256=78CBDF90D74B2BE1A5C69190D75CC98558E97F70153CA900AC2B7AB31355C341,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038596Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:53.093{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=467CA0BCB5D93B2CB4F6F74EEA2FF713,SHA256=D3DD53B2BCCF747A5F2347A78D33E1146373EC39492BC58D7E86FF4D409243B9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062026Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.831{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062025Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.800{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062024Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.631{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062023Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.600{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062022Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.600{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062021Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.562{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062020Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.562{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062019Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.515{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062018Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.362{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062017Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.362{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062016Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.362{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000062015Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.331{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062014Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.047{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000062013Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.047{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 23542300x800000000000000062031Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:54.862{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DFB253A9B7EAAB10B09AB8628C1686BE,SHA256=09C19101CB64947C2B1910D029658970315EB91B2B8D37B8709AC83A7DAE2A3A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038597Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:54.108{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A51E27F0D6CF120B76AEFEAD4E346B8,SHA256=02B7F24458421BA03CA67DD23ADA9A9C8D809759EE79FDFE44E55203317D75CA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062030Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:54.563{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062033Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:55.883{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C58AE07310F82C7693176F052680A57,SHA256=D776FD3029D1434C82BC6ABCC9C40CF364CC6F86DE14045FE227C9D6E3763C25,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038599Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:52.291{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50563-false10.0.1.12-8000- 23542300x800000000000000038598Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:55.124{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B825B176BE1DC426D803E837CBFBC5B6,SHA256=92DE2D10F1BC39BA79A1BBE0846FE35FD7B125716D5ED23E1FD1CA7668075375,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062032Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:53.198{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51049-false10.0.1.12-8000- 23542300x800000000000000062034Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:56.899{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=016470674B2AEBAB5FB6666B69EBF1D8,SHA256=4D5BFC7028F1E91300BEC9CA9311539D3D2FA622C0B4039F18C246F513F90768,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038600Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:56.140{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=40B72974D633D0416FD9E844074C540A,SHA256=51C3DBD3616A7BD3CB4AD7FF8FCC28482B9B1EC45AD8151F99708CC111090B22,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062035Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:57.914{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D78895E574F0A2EDEA0FF9EFC54BA4C8,SHA256=B8E3FF39A6D3E3B8F724259E0F73BD2627114B957B72B99232374FD71F6AFCBA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038601Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:57.374{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3537C51D95DAF8B6B9BEA5A6AF69BB2E,SHA256=1D130AE383BC1017146E99957D7F9A1E6A5DD731105C826AC3385FF96D6A9A9F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062046Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:58.960{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C85EBA7FA19B12201DE7A97B4B8C6B76,SHA256=B335259884FEEEC6383851666317A3F930DBD8708B505D46FF6E5462D20A569A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038602Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:58.421{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD380BA022086C6CF7B12030C4EAC5AB,SHA256=E7856A60CF16D7DF7B86443158C416E97033FD5126354BED82701D15BDE016A9,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000062045Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x800000000000000062044Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x00407874) 13241300x800000000000000062043Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d751fd-0x7001788c) 13241300x800000000000000062042Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d75205-0xd1c5e08c) 13241300x800000000000000062041Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7520e-0x338a488c) 13241300x800000000000000062040Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x800000000000000062039Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x00407874) 13241300x800000000000000062038Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d751fd-0x7001788c) 13241300x800000000000000062037Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d75205-0xd1c5e08c) 13241300x800000000000000062036Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:04:58.298{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7520e-0x338a488c) 23542300x800000000000000062047Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:59.977{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D10DEFCEA5251507C6D322254651DD32,SHA256=DD4840C14B0296DD6DEF1DE4D86501C6D50D8116E0840517C31F3134941E47F2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038603Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:59.437{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=099B3EF47A45AE6C1DEDCE53E4A5F6FD,SHA256=429F919FC28BA261E34E833B659EF0EB7600A0E461B83D670943A412150C65F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062049Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:00.997{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8CC3436BB7739FD694DAFE97FD8DC441,SHA256=68E92D93493019F0AC0E328EF55499C08D422820E7EBC0CC27D365D9424E67B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038604Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:00.671{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC58D7D0B38FDFEC435CB90D27BA55F3,SHA256=7A1FAA7952F8B32F5343B58B4E66A1B4ED97294FCFDB6E074C6C62332DBA87BF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062048Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:58.295{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51050-false10.0.1.12-8000- 23542300x800000000000000038606Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:01.876{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BE41E77A6C1539ACC8FCAD093957413,SHA256=C5B473C6EEFCE97B323A6D085DFCBD998686A5C8700DA2E7794F153E299D7022,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038605Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:04:58.230{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50564-false10.0.1.12-8000- 23542300x800000000000000038607Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:02.892{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=172F1470D087FE6BBD8329DBBC72F31F,SHA256=D3412BE40A7C5BE3864ECC38DFA04A76F622514AC24BA3253638B2DD691F6DAC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062059Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:04:59.898{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59811- 10341000x800000000000000062058Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.443{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062057Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.428{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062056Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.281{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062055Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.281{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062054Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.280{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062053Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.259{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062052Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.243{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062051Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.243{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062050Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:02.059{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C63428F6F6A8E30F3DEBB82DEB6A68F7,SHA256=C89C8D9506E31B8C1B07A7151D5C9067D6E08EDA14B74D0F637C1158723BD702,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038608Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:03.923{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C023540FCB0855AD246221A7C2EAE16A,SHA256=FAD64A12E34632340A45DE400242C81827EDFB414FA6F33CC77DD541D6098219,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062071Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.858{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062070Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.842{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062069Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.728{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062068Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.728{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062067Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.728{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062066Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.680{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804664C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+6497|C:\Windows\System32\SHCORE.dll+6387|C:\Windows\System32\SHCORE.dll+62fd|C:\Windows\System32\SHCORE.dll+620a|C:\Windows\System32\SHELL32.dll+a56d0|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF801E4CE48C8)|UNKNOWN(FFFFFE2B934B4A68)|UNKNOWN(FFFFFE2B934B4BE7)|UNKNOWN(FFFFFE2B934AF271)|UNKNOWN(FFFFFE2B934B0C3A)|UNKNOWN(FFFFFE2B934AEEF6)|UNKNOWN(FFFFF801E49FBE03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+a8f2b|C:\Windows\System32\SHELL32.dll+6a98a|C:\Windows\System32\SHCORE.dll+33fad 10341000x800000000000000062065Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.680{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804664C:\Windows\Explorer.EXE{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+1c0e5|C:\Windows\System32\SHELL32.dll+a51b1|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF801E4CE48C8)|UNKNOWN(FFFFFE2B934B4A68)|UNKNOWN(FFFFFE2B934B4BE7)|UNKNOWN(FFFFFE2B934AF271)|UNKNOWN(FFFFFE2B934B0C3A)|UNKNOWN(FFFFFE2B934AEEF6)|UNKNOWN(FFFFF801E49FBE03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+a8f2b|C:\Windows\System32\SHELL32.dll+6a98a|C:\Windows\System32\SHCORE.dll+33fad|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062064Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.680{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms~RF408d73.TMPMD5=051D85F6B4DE3E582C6B6ED1B6A70EE1,SHA256=C4CA60A7AD0E127DB0626B3240D5263E1B131F45DBA387BB8DB6134A45B35A36,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062063Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.658{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062062Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.658{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062061Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.658{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062060Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:03.096{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB8E1B9453F170099AE8C8DA1F821645,SHA256=4F27FF4520EE5710FE7FE40D3261C64A53C57A0859F805F432A96448E981E68F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038609Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:04.924{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D6F70089FDF7599B8D4F9CA3EA7C9AB,SHA256=C9FFF9F1F06621B4FEC866E720333E623097D98DCE15A8B56378B32A8C716EF8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062081Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.857{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062080Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.841{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062079Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.757{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062078Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.757{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062077Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.757{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062076Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.679{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062075Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.679{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062074Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.679{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062073Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:01.366{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local63185- 23542300x800000000000000062072Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.111{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7EC60B24E94D8291DC49FDA0FCDC6035,SHA256=125DACB002B01BEC7B0F5FE1BC415E95AC049D5991E23CEAD648E06294768C3D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038611Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:05.954{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=65B9C27AD4F72EF5CD5FE144209EAA18,SHA256=DEFF3DDB622A91BB3A0E6040A3034319D483E6140D8FB02BA57D0A703C1F9D2E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062086Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:05.898{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062085Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:05.811{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062084Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:05.157{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EC185D8BEC5AA9A3F63B83E53DEE150,SHA256=1651ADA8BE4A6DE1EC38159FFB762A836C47AB0C3CCD516A7FDC25C457F8B4B0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062083Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:05.157{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000038610Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:03.230{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50565-false10.0.1.12-8000- 10341000x800000000000000062082Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:05.141{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062131Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.882{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+16ccef2|C:\Program Files\Mozilla Firefox\xul.dll+16b0c43|C:\Program Files\Mozilla Firefox\xul.dll+17aec82|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0 10341000x800000000000000062130Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.882{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062129Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.882{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000062128Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.882{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+3021a51|C:\Program Files\Mozilla Firefox\xul.dll+3021559|C:\Program Files\Mozilla Firefox\xul.dll+3025257|C:\Program Files\Mozilla Firefox\xul.dll+30273cf|C:\Program Files\Mozilla Firefox\xul.dll+67fe56|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715 10341000x800000000000000062127Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.881{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+3021a51|C:\Program Files\Mozilla Firefox\xul.dll+3020ddd|C:\Program Files\Mozilla Firefox\xul.dll+302a297|C:\Program Files\Mozilla Firefox\xul.dll+3062b7f|C:\Program Files\Mozilla Firefox\xul.dll+302442c|C:\Program Files\Mozilla Firefox\xul.dll+30273cf|C:\Program Files\Mozilla Firefox\xul.dll+67fe56|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0 10341000x800000000000000062126Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062125Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062124Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062123Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062122Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062121Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062120Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062119Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062118Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062117Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062116Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062115Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062114Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062113Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062112Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062111Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062110Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062109Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062108Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062107Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062106Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062105Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062104Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062103Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062102Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062101Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062100Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062099Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062098Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062097Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062096Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062095Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.745{7CDEDE96-F0D1-60AD-0D00-00000000C501}892912C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062094Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:04.196{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51051-false10.0.1.12-8000- 10341000x800000000000000062093Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.298{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890 10341000x800000000000000062092Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.298{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd 23542300x800000000000000062091Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.229{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E872BD18DAF0FC2095FDE1FF9203A90F,SHA256=3AE690AC407411F3C69AD9CDEFC90E77161CF16C467D77980182CC7CCB3F1129,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062090Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.161{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000062089Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.161{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000062088Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.045{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062087Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.045{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000062142Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.777{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062141Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.777{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062140Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.708{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062139Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.677{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062138Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.492{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=97C8F9C42994F6727BA9746A38AC5EC9,SHA256=E33270303E41BA86FD28DEA83EDB5A31E9E8C609090B31A0328FECDF6DD2298D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062137Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.339{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062136Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.308{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062135Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.308{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062134Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.258{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038612Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:07.142{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C1F00991C514A769E0CF6170A0E9EEAF,SHA256=F875AC2E424637D9B72AF34603E4761CF3DD5080868F9F8C9594D816C50576FD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062133Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.244{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062132Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:07.242{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062148Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:08.856{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062147Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:08.677{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062146Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.059{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local51052-false185.199.108.133cdn-185-199-108-133.github.com443https 23542300x800000000000000062145Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:08.624{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\permissions.sqlite-journalMD5=1CEA8F18D7677D0D0C5AD87276676419,SHA256=F1F692049B2623D41963B8D526A5E5713C474422FDFA1A10BE47060010F535C7,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062144Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:08.624{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062143Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:08.277{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=387BA9579C6B87CB366953D9B711C160,SHA256=5E6122DD2461C69EAF9B38AB96CFAF5A116C01DC8FD3018411F1CD19E5B2CECE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038613Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:08.173{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F78E03ECFD8EAD4CDE8A4B1F6F2A9241,SHA256=E489FEA4DDFC5D64B8BE46BF4AFE1FAFC4EF041FBB2FC8A36817A59FBD925C49,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038614Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:09.189{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F810D4286C8330A50108C4E4AEC3A68,SHA256=0738A04FAAE8FA348CD9457C6D14BE3CEF61F81332255567F949EC4F297305C2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062150Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:06.929{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local59246- 23542300x800000000000000062149Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:09.294{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B722C83AF5FFAA00C24CE200B72CFE15,SHA256=4972F63676CA50B6D6149DC34010F312A5238561A0068D711310720883724626,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062151Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:10.296{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2170CA9AFF95C172E22E4CC30FDB1CA,SHA256=0EAFA3F9F455A9F8A580859F0EB02E08BDE797EF0888F1BBDA31065D662C1AC1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038616Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:08.261{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50566-false10.0.1.12-8000- 23542300x800000000000000038615Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:10.298{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8EBB16754DA966941A3F6CEDB4DCD21D,SHA256=BD7B2D761EFB5064181DD3398DFDB20D5147EACF75C36008CE64863D65A6FF44,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062153Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:09.259{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51053-false10.0.1.12-8000- 23542300x800000000000000062152Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:11.313{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=19EB147A73AE1D77A657AD2FE54B548E,SHA256=93C95392BE6EE5443660CA57A4E1A1BB7A496110A6C2312BA0AC380ED765EDF9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038617Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:11.314{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37C0EABDB3DB1DD62BC445EF7E4ABBA9,SHA256=600DF2281EE3CE067F409B96276D2C4E91CA1287A66EEF06BE80D8D43845316C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062155Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:12.627{7CDEDE96-F0CF-60AD-0B00-00000000C501}632372C:\Windows\system32\lsass.exe{7CDEDE96-F0B3-60AD-0100-00000000C501}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 23542300x800000000000000062154Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:12.343{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF74F2BCB0CEDAE87052260F36B6844F,SHA256=0506794BFC641DAA765473B426C198BB5A358A64EE1AC6B7F9CE468BEDFF3248,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038618Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:12.330{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9990B1901AD5D075E0421670C3E0F0C1,SHA256=056691783D50A046907F2CD8E57307AFA3ABC41423E54643FCB540213AA914D9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062175Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.980{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062174Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.980{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062173Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:11.747{7CDEDE96-F0B3-60AD-0100-00000000C501}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51054-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local445microsoft-ds 354300x800000000000000062172Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:11.747{7CDEDE96-F0B3-60AD-0100-00000000C501}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51054-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local445microsoft-ds 10341000x800000000000000062171Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.811{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062170Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.795{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062169Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.779{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062168Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.758{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062167Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.742{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062166Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.658{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062165Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.658{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=72AC693517C66722744569266BF909D5,SHA256=EBE534A437473B85F63AD4D034AFF0F1CD8E73CFA9CBEBA1B83AF2942FA299A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062164Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.658{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=15BE8495CDB9C44C5419ED0420BD5302,SHA256=4DD283453797A72642CE9029BBF58F1F4FE4D2A0B85A34574A996CB015AB5FCC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062163Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.642{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062162Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.627{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+16ccef2|C:\Program Files\Mozilla Firefox\xul.dll+16b0c43|C:\Program Files\Mozilla Firefox\xul.dll+17aec82|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1 10341000x800000000000000062161Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.627{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2c2935b|C:\Program Files\Mozilla Firefox\xul.dll+2c292d9|C:\Program Files\Mozilla Firefox\xul.dll+2ced2b6|C:\Program Files\Mozilla Firefox\xul.dll+2ceac59|C:\Program Files\Mozilla Firefox\xul.dll+2ce9384 10341000x800000000000000062160Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.627{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000062159Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.627{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2c2935b|C:\Program Files\Mozilla Firefox\xul.dll+2c292d9|C:\Program Files\Mozilla Firefox\xul.dll+2ced2b6|C:\Program Files\Mozilla Firefox\xul.dll+2ceac59|C:\Program Files\Mozilla Firefox\xul.dll+2ce9384 10341000x800000000000000062158Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.611{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000062157Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.611{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+3021a51|C:\Program Files\Mozilla Firefox\xul.dll+3020ddd|C:\Program Files\Mozilla Firefox\xul.dll+302a297|C:\Program Files\Mozilla Firefox\xul.dll+67fe56|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2c2935b|C:\Program Files\Mozilla Firefox\xul.dll+2c292d9 23542300x800000000000000062156Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.376{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=699FA7A57C3131F90CF21FB784648D66,SHA256=070BF8675E9524564BF6BD9D43C33C8E211E9C254C1F238CEBD211895B4A7EF4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038619Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:13.330{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5CBAD7E4DDC72FD80FAE7B51D1D631B0,SHA256=5E80950999474C4202275075165E4A4EA7F6010A662912030DD995DDDC335212,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062185Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.875{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A6744411974AF381DC87716B3DD39658,SHA256=BAF1F7C602A8D93454BE0E4F161213C1157719272A69FE1845EDFC107CF71459,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062184Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.758{7CDEDE96-F0D1-60AD-1100-00000000C501}388NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=D49B06FED3ACA2A5FDB5A2E41FD4829B,SHA256=82A44C695F27356CF727CA274AA6186A56BA59F841DEC966142D1E589718FA5E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062183Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.443{7CDEDE96-F0D1-60AD-1600-00000000C501}13244124C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062182Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.443{7CDEDE96-F0D1-60AD-1600-00000000C501}13244124C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038620Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:14.345{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=764CB91077D28BB9FE5BB11D99B2EAB7,SHA256=6992A633EB6F51EF1D6374728BCD26E9EB2D58A4F7304AFEA59D8E2B5A6C7040,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062181Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.227{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062180Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.197{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062179Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.080{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062178Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.042{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062177Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.027{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062176Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:13.998{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062186Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:15.449{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64D32AE9C41B669B19929DF677205B9A,SHA256=1A69EBC9322F5B4BB4D8E6DBCBA8C8F7023B548968BAB025B96D0DB194026B74,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038621Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:15.346{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=110EBB668E5EDC650A03E99B598AA976,SHA256=77409C6498B67B3070C1223540F47FA0969CBB2B8DD7D6FD65E2EBD5E9E29722,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062193Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:16.977{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062192Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:14.337{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51055-false10.0.1.12-8000- 10341000x800000000000000062191Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:16.865{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062190Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:16.802{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062189Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:16.687{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062188Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:16.634{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062187Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:16.534{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7753F013421D9C8F5B1E55E77934A1B8,SHA256=126A8ADD6DF488D13C84C5B5C1E773E283BB9B2C6BE9206DF2E697E6A987A7E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038622Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:16.361{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D9DB9634E2A155D7F8E4AB86BA05C07,SHA256=4D4CC0F3D314D6F080D7BF261DA57A792830074E0F7156D84100AB0182BA47D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062198Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:17.559{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3DCAB24738CF6DA0F913206911FAC9A8,SHA256=F10C52D5FFD241AEA31D346471E071A4BBCC052DCA4733A10DD32A6702039A12,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038624Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:17.377{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A7EBC0F338F94920D3A247BA4D185BB3,SHA256=56AE191968613FB1FC308083AB99EA2CE23AD5A17E7DF4B09E80C594663F6F82,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062197Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:17.228{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062196Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:17.190{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062195Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:17.059{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062194Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:17.028{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000038623Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:14.183{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50567-false10.0.1.12-8000- 10341000x800000000000000062201Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:18.942{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062200Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:18.927{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062199Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:18.574{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53738E8C6C8435364804D14145D201B2,SHA256=105DBF82AEEC72E435A85E6449C3D783A219ECA392AE0EA73C68A7B2F9050071,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038625Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:18.611{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE515327025DA505AF3ACB152DE8A691,SHA256=DD21921D6CB58D7999E437BA946D52A80EAC29B036515B8ED0C603E96BE2BD1C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062212Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.744{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062211Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.744{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062210Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.676{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062209Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.676{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062208Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.645{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000062207Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.645{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 23542300x800000000000000062206Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.575{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C4088A70B9372FD32574261C91438FA,SHA256=CCAD97945D92A6232E2242EDABB59C8E075851D4190BE09122E2E93B5377A2B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038626Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:19.611{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=54CDCC404378A8EDBAACDCD930ABC30B,SHA256=1D14B16AC0190BBCA8C217CF5D7C327E096CCBEDB4BC6C8FFD423E0C9AB084AA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062205Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.528{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062204Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.528{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000062203Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.143{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062202Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:19.143{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038627Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:20.830{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C1BAA951F38F5482119B0C4765B6D91,SHA256=967CF873DA8C586B417B8DC595F5248EF5378A5EBE95B0222D3CFA34035C4BEE,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062217Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:20.643{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062216Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:20.643{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062215Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:20.590{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E704EE865196043C76722D41E14791B0,SHA256=12588B18CF732893E349A419FBBC3528C4832C67F12C7B07E240A6B006012B8A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062214Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:20.137{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062213Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:20.137{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062221Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.990{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062220Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.990{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 23542300x800000000000000062219Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.609{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A756D4A96B69E525572A569537F5E0BC,SHA256=976F7C0CFD910B31613BA498FE101D9BADFD7410F375EFB0D01594348EEC2E62,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062218Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.107{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062237Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:20.246{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51056-false10.0.1.12-8000- 10341000x800000000000000062236Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.874{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062235Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.674{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062234Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.642{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A2BEC88430D2A5D2582E69B517593D69,SHA256=A440DF95C51FBF9B75A38EB7165AD94124E102691D53CB38FC9F3AF8FACAF262,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062233Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.530{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890 354300x800000000000000038629Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:19.323{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50568-false10.0.1.12-8000- 23542300x800000000000000038628Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:22.065{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4FA25C4BE607712313FA48EE80C9DE1,SHA256=E9A205570CF5DA415BE6C403FADEA01895597B190F22D9832567D738984602A1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062232Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.530{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062231Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.530{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd 10341000x800000000000000062230Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.530{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000062229Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.530{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 10341000x800000000000000062228Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.489{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062227Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.489{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062226Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.443{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277 10341000x800000000000000062225Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.443{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb 10341000x800000000000000062224Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.174{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062223Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.090{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062222Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:22.090{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000062250Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.782{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-141.attackrange.local51057-false185.199.111.133cdn-185-199-111-133.github.com443https 354300x800000000000000062249Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.780{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local57809- 354300x800000000000000062248Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.776{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local58339- 23542300x800000000000000062247Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.689{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2888FFE6E512776C3C2C382450E2AD95,SHA256=78167F81E7A147252510A2A7457DEE19487B9C4314A9A30D75F828106B3EBDD8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038630Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:23.113{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=307E92BB931E79D4FB3B65EDB083EE93,SHA256=4E5076558AD1AE6097DC610CB3D994D59BCFE56F12B580CDEB69DFB164DC8F8D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062246Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.173{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062245Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.142{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062244Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.142{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062243Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.142{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062242Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.127{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062241Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.111{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062240Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.011{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+16ccef2|C:\Program Files\Mozilla Firefox\xul.dll+16b0c43|C:\Program Files\Mozilla Firefox\xul.dll+17aec82|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1 10341000x800000000000000062239Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.011{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120715e|C:\Program Files\Mozilla Firefox\xul.dll+16b1fec|C:\Program Files\Mozilla Firefox\xul.dll+69224b|C:\Program Files\Mozilla Firefox\xul.dll+17aeb52|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21|C:\Program Files\Mozilla Firefox\xul.dll+2c2a2c0|C:\Program Files\Mozilla Firefox\xul.dll+62d9e1|C:\Program Files\Mozilla Firefox\xul.dll+2de0715|C:\Program Files\Mozilla Firefox\xul.dll+2de5890|C:\Program Files\Mozilla Firefox\xul.dll+2de56f1|C:\Program Files\Mozilla Firefox\xul.dll+2de5277|C:\Program Files\Mozilla Firefox\xul.dll+2de4d3a 10341000x800000000000000062238Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.011{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1228a69|C:\Program Files\Mozilla Firefox\xul.dll+1228989|C:\Program Files\Mozilla Firefox\xul.dll+122607d|C:\Program Files\Mozilla Firefox\xul.dll+1226524|C:\Program Files\Mozilla Firefox\xul.dll+16cbe91|C:\Program Files\Mozilla Firefox\xul.dll+690c09|C:\Program Files\Mozilla Firefox\xul.dll+690b14|C:\Program Files\Mozilla Firefox\xul.dll+6908fd|C:\Program Files\Mozilla Firefox\xul.dll+690534|C:\Program Files\Mozilla Firefox\xul.dll+17aeb33|C:\Program Files\Mozilla Firefox\xul.dll+17aea84|C:\Program Files\Mozilla Firefox\xul.dll+68fa77|C:\Program Files\Mozilla Firefox\xul.dll+17abf14|C:\Program Files\Mozilla Firefox\xul.dll+17b587d|C:\Program Files\Mozilla Firefox\xul.dll+17a9e08|C:\Program Files\Mozilla Firefox\xul.dll+17aa25f|C:\Program Files\Mozilla Firefox\xul.dll+6800fd|C:\Program Files\Mozilla Firefox\xul.dll+65869f|C:\Program Files\Mozilla Firefox\xul.dll+64ebcb|C:\Program Files\Mozilla Firefox\xul.dll+2c2af21 23542300x800000000000000062254Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:24.707{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=62AD4DAE879D5FB82D2EDC25EC4054F3,SHA256=6404873180077B990F296B05C99CE8D5102060FBBE284B712BDF444045520523,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038632Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:24.910{266C2353-F0DB-60AD-1000-00000000C601}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=8DCCE08660673BBB07D9FFF39D35CDCF,SHA256=955ED8F74F9D7274239ADCFF63E59D0D0460DC7020A754F0AED2E9748D39AABB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038631Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:24.191{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4238F40AAA035963C3D64A0D950E550F,SHA256=430251C5CF820D7EE8792097629B24E476973004ACFFC8C099AC043A11A7250B,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000062253Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.791{7CDEDE96-003C-60AE-7C02-00000000C501}4140raw.githubusercontent.com0::ffff:185.199.111.133;::ffff:185.199.108.133;::ffff:185.199.109.133;::ffff:185.199.110.133;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000062252Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:24.541{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=625F82450F960F9AAFA488A8402C260A,SHA256=A618B0D03C6171DD549FF4F4AF16E0E09E6AF02F1F9B60A9876012E7312207A6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062251Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:24.541{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=72AC693517C66722744569266BF909D5,SHA256=EBE534A437473B85F63AD4D034AFF0F1CD8E73CFA9CBEBA1B83AF2942FA299A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062257Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:25.725{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=13C181F31E814F2223AC4DDFF7423420,SHA256=49BEDAA608B5C02433EBA036C751F668ABB70445FCBE97CB53363B45492C4002,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038633Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:25.285{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2BBD823CA582EA301B552A981441758A,SHA256=3A711DDED74C113D4EEBBCD000B06682226411062DC0B4F745CF2918B5AB3FD0,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000062256Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.794{7CDEDE96-003C-60AE-7C02-00000000C501}4140raw.githubusercontent.com9501-C:\Program Files\Mozilla Firefox\firefox.exe 22542200x800000000000000062255Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:21.792{7CDEDE96-003C-60AE-7C02-00000000C501}4140raw.githubusercontent.com0185.199.108.133;185.199.109.133;185.199.110.133;185.199.111.133;C:\Program Files\Mozilla Firefox\firefox.exe 23542300x800000000000000062259Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:26.740{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FADAEF124BCCB0A111E029E5C9ECC5D6,SHA256=1402E3178130E01BC4583399D2F9092B570F216CB089ECB062F67F8A887724AD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038634Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:26.379{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0DBFE4E8E1098311622F40C30A778137,SHA256=7BCEE89DAA1D101A1584C4AA21F3956867DFD0679562A64F7C0B2F78FD0CCF26,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062258Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:23.060{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local65129- 23542300x800000000000000062292Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.887{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1251E34E80618403D8A2D9AD16AD3319,SHA256=81C482B58F8A1C538D5CFFF14EB8AAD5A77F66A2C61D46A4AE1CA20012F634EB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038636Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:25.263{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50569-false10.0.1.12-8000- 23542300x800000000000000038635Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:27.396{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=01FC09349667B1D777F2250AC6ED9620,SHA256=73273FC6F12A5394B257DB3E6C3371FE51475F338A45FB61D9BA850553BB9249,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062291Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.740{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41968|C:\Windows\system32\windows.cortana.Desktop.dll+16557|C:\Windows\system32\windows.cortana.Desktop.dll+12d9b|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062290Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.740{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41680|C:\Windows\system32\windows.cortana.Desktop.dll+92dc|C:\Windows\system32\windows.cortana.Desktop.dll+12d31|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062289Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.740{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802456C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062288Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.740{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802456C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062287Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.724{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062286Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.724{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\execmodelclient.dll+8e62|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 10341000x800000000000000062285Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.724{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\execmodelclient.dll+8d5e|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 10341000x800000000000000062284Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.708{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062283Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.708{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062282Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805956C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062281Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805956C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062280Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000062279Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000062278Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802724C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b13af|C:\Windows\System32\SHELL32.dll+b3175|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062277Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802724C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b308e|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062276Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802724C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062275Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062274Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062273Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062272Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062271Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062270Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062269Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D1-60AD-0D00-00000000C501}8925044C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+1644|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062268Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a384|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062267Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+489d|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a2ed|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062266Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.687{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+489d|C:\Windows\SYSTEM32\psmserviceexthost.dll+1a2ed|C:\Windows\SYSTEM32\psmserviceexthost.dll+11055|C:\Windows\SYSTEM32\psmserviceexthost.dll+108cf|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062265Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.671{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062264Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.671{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062263Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.671{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062262Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.671{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363380C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062261Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.671{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805988C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062260Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:27.671{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805988C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038637Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:28.428{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CE42E0CAD6FCCBA8FB928C2D83C289A9,SHA256=96F7CA27C751F1B2D4B1D6C1872F3F86A3EBCC4518930752DD6CA68B964DA446,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062293Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:25.343{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51058-false10.0.1.12-8000- 23542300x800000000000000038638Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:29.459{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=507A9B343B5FB5DED15E3CBE8FA1168D,SHA256=C2340E3B8BAF9EAFA93A4DE754398F42BE12AEE0D6288E3CC35EFD07F9D290DA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062316Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.987{7CDEDE96-F8F4-60AD-9301-00000000C501}4980ATTACKRANGE\AdministratorC:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exeC:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\6367EBB6\microsoft.windows[1].xmlMD5=75A4DCDD9285F8719938E6001912C636,SHA256=FF98CA75C962D77F9D79BAAF0D92988E74A31453A5EA1C4FC21BFE857565C353,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062315Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.940{7CDEDE96-F0D1-60AD-1600-00000000C501}13242480C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-A002-00000000C501}6128C:\Windows\system32\DllHost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062314Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.940{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-A002-00000000C501}6128C:\Windows\system32\DllHost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062313Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.937{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-A002-00000000C501}6128C:\Windows\system32\DllHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062312Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.919{7CDEDE96-F8F0-60AD-7E01-00000000C501}13363908C:\Windows\system32\csrss.exe{7CDEDE96-0149-60AE-A002-00000000C501}6128C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062311Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.919{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0149-60AE-A002-00000000C501}6128C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062310Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.919{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-A002-00000000C501}6128C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062309Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.887{7CDEDE96-F0D1-60AD-1600-00000000C501}13242480C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-9F02-00000000C501}5840C:\Windows\system32\DllHost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062308Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.887{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-9F02-00000000C501}5840C:\Windows\system32\DllHost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062307Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.872{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-9F02-00000000C501}5840C:\Windows\system32\DllHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062306Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.872{7CDEDE96-F8F4-60AD-9301-00000000C501}4980ATTACKRANGE\AdministratorC:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exeC:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\6367EBB6\microsoft.windows[1].xmlMD5=75A4DCDD9285F8719938E6001912C636,SHA256=FF98CA75C962D77F9D79BAAF0D92988E74A31453A5EA1C4FC21BFE857565C353,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062305Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.872{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-0149-60AE-9F02-00000000C501}5840C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f 23542300x800000000000000062304Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.872{7CDEDE96-F8F4-60AD-9301-00000000C501}4980ATTACKRANGE\AdministratorC:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exeC:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\6367EBB6\microsoft.windows[1].xmlMD5=C1DDEA3EF6BBEF3E7060A1A9AD89E4C5,SHA256=B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062303Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.856{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062302Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.856{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062301Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.856{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-0149-60AE-9F02-00000000C501}5840C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062300Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.856{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-0149-60AE-9F02-00000000C501}5840C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35af2|c:\windows\system32\rpcss.dll+3c90d|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062299Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.712{7CDEDE96-F0E1-60AD-3000-00000000C501}2240NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062298Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.648{7CDEDE96-F8F4-60AD-9301-00000000C501}4980ATTACKRANGE\AdministratorC:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exeC:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\6367EBB6\microsoft.windows[1].xmlMD5=C1DDEA3EF6BBEF3E7060A1A9AD89E4C5,SHA256=B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062297Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.638{7CDEDE96-F8F4-60AD-9301-00000000C501}4980ATTACKRANGE\AdministratorC:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exeC:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\6367EBB6\microsoft.windows[1].xmlMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062296Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.626{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804664C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+6497|C:\Windows\System32\SHCORE.dll+6387|C:\Windows\System32\SHCORE.dll+62fd|C:\Windows\System32\SHCORE.dll+620a|C:\Windows\System32\SHELL32.dll+a56d0|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF801E4CE48C8)|UNKNOWN(FFFFFE2B934B4A68)|UNKNOWN(FFFFFE2B934B4BE7)|UNKNOWN(FFFFFE2B934AF271)|UNKNOWN(FFFFFE2B934B0C3A)|UNKNOWN(FFFFFE2B934AEEF6)|UNKNOWN(FFFFF801E49FBE03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+a8f2b|C:\Windows\System32\SHELL32.dll+6a98a|C:\Windows\System32\SHCORE.dll+33fad 10341000x800000000000000062295Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.625{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804664C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+1c0e5|C:\Windows\System32\SHELL32.dll+a51b1|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF801E4CE48C8)|UNKNOWN(FFFFFE2B934B4A68)|UNKNOWN(FFFFFE2B934B4BE7)|UNKNOWN(FFFFFE2B934AF271)|UNKNOWN(FFFFFE2B934B0C3A)|UNKNOWN(FFFFFE2B934AEEF6)|UNKNOWN(FFFFF801E49FBE03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+a8f2b|C:\Windows\System32\SHELL32.dll+6a98a|C:\Windows\System32\SHCORE.dll+33fad|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062294Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:29.039{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0ADE056DC142F7E88E6AAF3390A7EE9C,SHA256=9FFE7A311D9017A170D3D308F3F2716D83D950683BA198C23B08E5596023A984,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038639Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:30.553{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DEECFD40BD1629153C6AFB2367D3BB2,SHA256=2FD542125CFBA1A4DE2E1ECB6BDCF6DF97A86E9908B93134C74F4D51AD14072E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062352Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.890{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C21937E4C0D8E2B8E7662C29AB9C685D,SHA256=3FF0A9CB784ABF647C7CC7FF0F9CA493AF5AA4E9E4BBF91341F9E3F4E86083C3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062351Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.890{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=625F82450F960F9AAFA488A8402C260A,SHA256=A618B0D03C6171DD549FF4F4AF16E0E09E6AF02F1F9B60A9876012E7312207A6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062350Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.304{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8AF4DB35BE0899E9E1D490557114E2C3,SHA256=1AC09F26BEE24FCBD560834E356B8D44C31D9504D94DD7C3D295BDF45D937BAE,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062349Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40486000C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062348Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40486000C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062347Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062346Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062345Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062344Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062343Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40486000C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41968|C:\Windows\system32\windows.cortana.Desktop.dll+26297|C:\Windows\system32\windows.cortana.Desktop.dll+214fb|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062342Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.220{7CDEDE96-F8F2-60AD-8501-00000000C501}40486000C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41680|C:\Windows\system32\windows.cortana.Desktop.dll+92dc|C:\Windows\system32\windows.cortana.Desktop.dll+21491|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062341Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40486000C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062340Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40486000C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062339Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062338Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062337Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062336Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062335Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41968|C:\Windows\system32\windows.cortana.Desktop.dll+26297|C:\Windows\system32\windows.cortana.Desktop.dll+214fb|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062334Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.188{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41680|C:\Windows\system32\windows.cortana.Desktop.dll+92dc|C:\Windows\system32\windows.cortana.Desktop.dll+21491|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062333Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062332Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062331Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062330Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062329Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062328Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062327Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41968|C:\Windows\system32\windows.cortana.Desktop.dll+26297|C:\Windows\system32\windows.cortana.Desktop.dll+214fb|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062326Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.155{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41680|C:\Windows\system32\windows.cortana.Desktop.dll+92dc|C:\Windows\system32\windows.cortana.Desktop.dll+21491|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062325Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.088{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062324Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.088{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062323Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.088{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+1a962|C:\Windows\system32\windows.cortana.onecore.dll+16e12|C:\Windows\system32\windows.cortana.onecore.dll+16d5b|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062322Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.088{7CDEDE96-F8F2-60AD-8501-00000000C501}40485996C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062321Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.088{7CDEDE96-F8F2-60AD-8501-00000000C501}40485600C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 10341000x800000000000000062320Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.088{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.onecore.dll+1a8c3|C:\Windows\system32\windows.cortana.onecore.dll+6198|C:\Windows\system32\windows.cortana.onecore.dll+16cb1|C:\Windows\system32\windows.cortana.onecore.dll+1537|C:\Windows\system32\windows.cortana.onecore.dll+4a2d|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde 23542300x800000000000000062319Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.057{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B9450A021BF04A115A576AB2DF6DF35,SHA256=DEF5AE6B517B2790D9009F3AAD120FF22391202DF7CDA22CBC162F9DA66AFABC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062318Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.003{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41968|C:\Windows\system32\windows.cortana.Desktop.dll+26297|C:\Windows\system32\windows.cortana.Desktop.dll+214fb|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 10341000x800000000000000062317Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.003{7CDEDE96-F8F2-60AD-8501-00000000C501}40483916C:\Windows\System32\RuntimeBroker.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\system32\windows.cortana.Desktop.dll+418c2|C:\Windows\system32\windows.cortana.Desktop.dll+41680|C:\Windows\system32\windows.cortana.Desktop.dll+92dc|C:\Windows\system32\windows.cortana.Desktop.dll+21491|C:\Windows\system32\windows.cortana.Desktop.dll+15c7|C:\Windows\system32\windows.cortana.Desktop.dll+44bd|C:\Windows\System32\combase.dll+ae6fa|C:\Windows\System32\combase.dll+a54bd|C:\Windows\System32\RuntimeBroker.exe+12d1|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\combase.dll+64de3|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d 23542300x800000000000000038640Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:31.569{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C076740CDD37B55B808AE3C65E0EC004,SHA256=2437920E408D0D79F2760EB148D451B360E9B8DC7888FECD4B7C4FC36206C10F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062406Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802248C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+15d19|C:\Windows\System32\SHELL32.dll+b1b50|C:\Windows\System32\SHELL32.dll+f744|C:\Windows\Explorer.EXE+1e118|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062405Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802724C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+15d19|C:\Windows\System32\SHELL32.dll+b1b50|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062404Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802724C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062403Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802248C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+f744|C:\Windows\Explorer.EXE+1e118|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062402Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802248C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+15d19|C:\Windows\System32\SHELL32.dll+b1b50|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+1e03a|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062401Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802248C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b3057|C:\Windows\Explorer.EXE+1e03a|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062400Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.845{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802248C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\Explorer.EXE+1f054|C:\Windows\Explorer.EXE+1f000|C:\Windows\Explorer.EXE+1dfec|C:\Windows\Explorer.EXE+1e249|C:\Windows\Explorer.EXE+1df79|C:\Windows\Explorer.EXE+3c407|C:\Windows\System32\windows.storage.dll+13bd5f|C:\Windows\System32\windows.storage.dll+13aaeb|C:\Windows\System32\windows.storage.dll+13900f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062399Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.723{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-014B-60AE-A202-00000000C501}5784C:\Program Files\Notepad++\updater\gup.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062398Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.723{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-014B-60AE-A202-00000000C501}5784C:\Program Files\Notepad++\updater\gup.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062397Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.708{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062396Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.708{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062395Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+15d19|C:\Windows\System32\SHELL32.dll+b1b50|C:\Windows\System32\SHELL32.dll+b2a80|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062394Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+b1604|C:\Windows\System32\SHELL32.dll+b2a80|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062393Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.708{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804800C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062392Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.645{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062391Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.640{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-014B-60AE-A202-00000000C501}5784C:\Program Files\Notepad++\updater\gup.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062390Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.640{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062389Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.640{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062388Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.639{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062387Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.639{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062386Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.639{7CDEDE96-014B-60AE-A102-00000000C501}5364288C:\Program Files\Notepad++\notepad++.exe{7CDEDE96-014B-60AE-A202-00000000C501}5784C:\Program Files\Notepad++\updater\gup.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\windows.storage.dll+16e61f|C:\Windows\System32\windows.storage.dll+16e295|C:\Windows\System32\windows.storage.dll+16dd86|C:\Windows\System32\windows.storage.dll+16f1f8|C:\Windows\System32\windows.storage.dll+16dbae|C:\Windows\System32\windows.storage.dll+fd025|C:\Windows\System32\windows.storage.dll+fd3a4|C:\Windows\System32\windows.storage.dll+fc9e0|C:\Windows\System32\SHELL32.dll+8e49f|C:\Windows\System32\SHELL32.dll+8e32c|C:\Windows\System32\SHELL32.dll+8e07c|C:\Windows\System32\SHELL32.dll+11c467|C:\Windows\System32\SHELL32.dll+11c3c5|C:\Windows\System32\SHELL32.dll+1378db|C:\Program Files\Notepad++\notepad++.exe+103989|C:\Program Files\Notepad++\notepad++.exe+151841|C:\Program Files\Notepad++\notepad++.exe+182086|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062385Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.625{7CDEDE96-014B-60AE-A202-00000000C501}5784C:\Program Files\Notepad++\updater\GUP.exe5.13WinGup for Notepad++WinGup for Notepad++Don HO don.h@free.frgup.exe"C:\Program Files\Notepad++\updater\gup.exe" -v7.95 -px64C:\Program Files\Notepad++\updater\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542HighMD5=EA20C0550A753BF194FA02A52A0CB932,SHA256=70FF333305CE2C4FBD5C583B3158A2A083D784C0F8A3D2AE09D55568E19BCD7E,IMPHASH=0AC02220E25075D21D6FCE74AEF267AF{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe"C:\Program Files\Notepad++\notepad++.exe" 10341000x800000000000000062384Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.623{7CDEDE96-F0D1-60AD-1200-00000000C501}404528C:\Windows\System32\svchost.exe{7CDEDE96-014B-60AE-A202-00000000C501}5784C:\Program Files\Notepad++\updater\gup.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\pcasvc.dll+ac96|c:\windows\system32\pcasvc.dll+aaf6|c:\windows\system32\pcasvc.dll+aab8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062383Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.607{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062382Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.607{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062381Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.592{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062380Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.576{7CDEDE96-F0D1-60AD-1600-00000000C501}1324708C:\Windows\system32\svchost.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062379Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.576{7CDEDE96-F0D1-60AD-1600-00000000C501}13241376C:\Windows\system32\svchost.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062378Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.445{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000062377Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.445{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+ba300|C:\Windows\System32\TwinUI.dll+ba677|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e 10341000x800000000000000062376Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.441{7CDEDE96-F0D1-60AD-1200-00000000C501}404528C:\Windows\System32\svchost.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\pcasvc.dll+ac96|c:\windows\system32\pcasvc.dll+aaf6|c:\windows\system32\pcasvc.dll+aab8|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 13241300x800000000000000062375Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.localInvDBSetValue2021-05-26 08:05:31.441{7CDEDE96-F0D1-60AD-1200-00000000C501}404C:\Windows\System32\svchost.exeHKU\S-1-5-21-3099192293-1001360012-1654889137-500\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\C:\Program Files\Notepad++\notepad++.exeBinary Data 10341000x800000000000000062374Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062373Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802456C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1ea06|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062372Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F8F3-60AD-8F01-00000000C501}45802456C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e95e|C:\Windows\SYSTEM32\twinapi.appcore.dll+1e3d1|C:\Windows\SYSTEM32\twinapi.appcore.dll+1dbcc|C:\Windows\SYSTEM32\twinapi.appcore.dll+1d777|C:\Windows\System32\TwinUI.dll+109196|C:\Windows\System32\TwinUI.dll+82af7|C:\Windows\System32\TwinUI.dll+beb2e|C:\Windows\System32\TwinUI.dll+beaf9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062371Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+739b|C:\Windows\SYSTEM32\psmserviceexthost.dll+ae34|C:\Windows\SYSTEM32\psmserviceexthost.dll+7bae|C:\Windows\SYSTEM32\psmserviceexthost.dll+12141|C:\Windows\SYSTEM32\psmserviceexthost.dll+170e8|C:\Windows\SYSTEM32\resourcepolicyserver.dll+12326|C:\Windows\SYSTEM32\resourcepolicyserver.dll+bac5|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062370Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D1-60AD-1200-00000000C501}4045368C:\Windows\System32\svchost.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\pcasvc.dll+52e4|c:\windows\system32\pcasvc.dll+58a9|c:\windows\system32\pcasvc.dll+5b49|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062369Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D1-60AD-1200-00000000C501}4045368C:\Windows\System32\svchost.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1440C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\pcasvc.dll+5bab|c:\windows\system32\pcasvc.dll+5b07|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062368Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F8F2-60AD-8901-00000000C501}19404224C:\Windows\system32\taskhostw.exe{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\MSCTF.dll+af11|C:\Windows\System32\MSCTF.dll+b489|C:\Windows\System32\MSCTF.dll+be73|C:\Windows\System32\MSCTF.dll+3d832|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062367Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062366Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062365Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062364Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062363Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F8F0-60AD-7E01-00000000C501}13361996C:\Windows\system32\csrss.exe{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062362Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.423{7CDEDE96-F8F3-60AD-8F01-00000000C501}45805324C:\Windows\Explorer.EXE{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\windows.storage.dll+16e61f|C:\Windows\System32\windows.storage.dll+16e295|C:\Windows\System32\windows.storage.dll+16dd86|C:\Windows\System32\windows.storage.dll+16f1f8|C:\Windows\System32\windows.storage.dll+16dbae|C:\Windows\System32\windows.storage.dll+fd025|C:\Windows\System32\windows.storage.dll+fd3a4|C:\Windows\System32\windows.storage.dll+fc9e0|C:\Windows\System32\windows.storage.dll+1664ae|C:\Windows\System32\windows.storage.dll+1661a2|C:\Windows\System32\SHELL32.dll+90ee1|C:\Windows\System32\SHELL32.dll+8fd46|C:\Windows\System32\SHELL32.dll+d0c11|C:\Windows\System32\SHELL32.dll+b6e2e|C:\Windows\System32\windows.storage.dll+2d1a2|C:\Windows\System32\windows.storage.dll+2ce99|C:\Windows\System32\windows.storage.dll+2cd6f|C:\Windows\System32\SHELL32.dll+d0c97|C:\Windows\System32\SHELL32.dll+b6e2e|C:\Windows\System32\SHELL32.dll+1721db 154100x800000000000000062361Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.381{7CDEDE96-014B-60AE-A102-00000000C501}5364C:\Program Files\Notepad++\notepad++.exe7.95Notepad++ : a free (GPL) source code editorNotepad++Don HO don.h@free.frnotepad++.exe"C:\Program Files\Notepad++\notepad++.exe" C:\Program Files\Notepad++\ATTACKRANGE\Administrator{7CDEDE96-F8F1-60AD-54C9-100000000000}0x10c9542HighMD5=45833E3CFFD3716546665DCE0C343F2E,SHA256=5AEC02154C9A23F5D77B11853691449063AA0EF3988C4EB30048DEBBCEC8B947,IMPHASH=DE4B8987D5ADB218127887FA4130E9E8{7CDEDE96-F8F3-60AD-8F01-00000000C501}4580C:\Windows\explorer.exeC:\Windows\Explorer.EXE /NOUACCHECK 10341000x800000000000000062360Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.360{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062359Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.360{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062358Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.360{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+892c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+925b|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+650d|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+1e1c|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+c6ae 10341000x800000000000000062357Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.360{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+892c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+658c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+64d9|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+1e1c|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+c6ae 10341000x800000000000000062356Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.360{7CDEDE96-F8F3-60AD-8F01-00000000C501}45804692C:\Windows\Explorer.EXE{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+892c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+64ad|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+1e1c|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6180f|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+5df06|C:\Windows\System32\combase.dll+5d6ba|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11b2c|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+5be0|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+635e|C:\Windows\System32\windows.immersiveshell.serviceprovider.dll+c6ae|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000062355Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.345{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062354Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.345{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062353Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.059{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A9FDBADA90D3971634D687E12A2E271F,SHA256=B569327A9B9A03D2401D875A37B85DAB3E588F8ABA19B246A6F1D5B29F50E8E4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038641Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:32.569{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=449FCB3D53E7D241BB249D71D07EF281,SHA256=2DFDF86B320EAC1C1A24F2F13B93351F91820E37A8AE60577C872DC7FB2C5802,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062411Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:32.941{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\prefs-1.jsMD5=D41D8CD98F00B204E9800998ECF8427E,SHA256=E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062410Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:28.809{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51059-false10.0.1.12-8089- 23542300x800000000000000062409Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:32.392{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C21937E4C0D8E2B8E7662C29AB9C685D,SHA256=3FF0A9CB784ABF647C7CC7FF0F9CA493AF5AA4E9E4BBF91341F9E3F4E86083C3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062408Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:32.192{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67A4CB1D753DEFFED95588BC0DF00627,SHA256=6EF712C14D15E016F9A0447253AD62F5390C3D6E2C46E6E1EFD6C39CBB73E30C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062407Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:32.192{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=207189B4AD6B1BD9CE35297E0FC6A73D,SHA256=2E6CE96355345367928EB9F734C85D2AC6E9E1A8C43FBE5EBD1B02744A5D8EB3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038643Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:30.342{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50570-false10.0.1.12-8000- 23542300x800000000000000038642Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:33.584{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F362678B331C72BA5F62352071332345,SHA256=A9034E2459929D0922C213B0153A2BE5F38846E1D06BFB0F2D9FDBAFD3ABA7E6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062417Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:31.358{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51061-false10.0.1.12-8000- 10341000x800000000000000062416Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:33.224{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c526|C:\Windows\SYSTEM32\resourcepolicyserver.dll+11927|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062415Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:33.224{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c526|C:\Windows\SYSTEM32\resourcepolicyserver.dll+11927|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062414Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:33.224{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c526|C:\Windows\SYSTEM32\resourcepolicyserver.dll+11927|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062413Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:33.224{7CDEDE96-F0D0-60AD-0C00-00000000C501}8363268C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c526|C:\Windows\SYSTEM32\resourcepolicyserver.dll+11927|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 23542300x800000000000000062412Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:33.193{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D89D50E7EE53D0E99F0DA2E96490CE91,SHA256=761C3C9B9A5175770B10B47FFC391EA80F1CABD9DE47891230DE042F7C78F46C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038644Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:34.600{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DBD9CF276461BA406C60500A3F5EAF1A,SHA256=DB11851FA8E02138EC5337E99EF1F9BF39B74C1DB1F8C38F3CA5C5B2ABAA7BDA,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000062420Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.834{00000000-0000-0000-0000-000000000000}5784notepad-plus-plus.org0::ffff:172.67.136.69;::ffff:104.21.26.128;<unknown process> 354300x800000000000000062419Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:30.834{00000000-0000-0000-0000-000000000000}5784<unknown process>-tcptruefalse10.0.1.14win-dc-141.attackrange.local51060-false172.67.136.69-443https 23542300x800000000000000062418Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:34.194{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5E530CAC1720E9B7E04506613722F18,SHA256=053EC342A83A05B56CE7D02DCB1EEFDECC7A87B1F13254A68BBAE6A5B8071877,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038645Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:35.600{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=161C0B36B6E06F7297A77A088B252F48,SHA256=ED833CB050B897224EF15E9EB2CF9D0F2548531C24FC1ED8102B1FAE458584C1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062422Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:32.561{7CDEDE96-F0E1-60AD-2A00-00000000C501}3012C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51048- 23542300x800000000000000062421Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:35.243{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=059DD67ED5BD2763D1BD14A3977C8D20,SHA256=13A70CCC495658D61B447F43465ACB2AAD3A4AB2CBD72405E2EA173EEF945142,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038673Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0150-60AE-6902-00000000C601}4036C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038672Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038671Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038670Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038669Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038668Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0150-60AE-6902-00000000C601}4036C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038667Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0150-60AE-6902-00000000C601}4036C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038666Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038665Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038664Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038663Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038662Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.630{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038661Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.631{266C2353-0150-60AE-6902-00000000C601}4036C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038660Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.614{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF4E7A10BF303C282DEB76BAB952FE49,SHA256=1D10D93392B6F3554890460C19E8B23E6254F4E14D77E405536AF81242AF9515,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062432Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.878{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062431Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.878{7CDEDE96-F0D0-60AD-0C00-00000000C501}8365400C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062430Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.878{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062429Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.878{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062428Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.878{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062427Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.878{7CDEDE96-F8F2-60AD-8601-00000000C501}10566120C:\Windows\system32\sihost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\SYSTEM32\usermgrcli.dll+1121|C:\Windows\System32\modernexecserver.dll+37dac|C:\Windows\System32\modernexecserver.dll+37d4f|C:\Windows\System32\modernexecserver.dll+375a6|C:\Windows\System32\modernexecserver.dll+1a1c4|C:\Windows\System32\modernexecserver.dll+3191d|C:\Windows\System32\modernexecserver.dll+32871|C:\Windows\System32\modernexecserver.dll+3278f|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062426Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.694{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+78b1|C:\Windows\SYSTEM32\psmserviceexthost.dll+74d7|C:\Windows\SYSTEM32\psmserviceexthost.dll+12fce|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062425Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.694{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9201-00000000C501}4880C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 10341000x800000000000000062424Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.694{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F8F4-60AD-9301-00000000C501}4980C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x3600C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\psmserviceexthost.dll+966a|C:\Windows\SYSTEM32\psmserviceexthost.dll+776e|C:\Windows\SYSTEM32\psmserviceexthost.dll+12f1c|C:\Windows\SYSTEM32\psmserviceexthost.dll+15b2b|C:\Windows\SYSTEM32\psmserviceexthost.dll+1011d|C:\Windows\SYSTEM32\psmserviceexthost.dll+104a0|C:\Windows\SYSTEM32\psmserviceexthost.dll+13952|C:\Windows\SYSTEM32\psmserviceexthost.dll+16139|C:\Windows\SYSTEM32\psmserviceexthost.dll+16c03|C:\Windows\SYSTEM32\resourcepolicyserver.dll+1a70e|C:\Windows\SYSTEM32\resourcepolicyserver.dll+14fc2|C:\Windows\SYSTEM32\resourcepolicyserver.dll+c61d|C:\Windows\SYSTEM32\resourcepolicyserver.dll+118d9|C:\Windows\SYSTEM32\resourcepolicyserver.dll+b91a|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c 23542300x800000000000000062423Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:36.263{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=63D5DBAC299243B48CD57006DE5C18B7,SHA256=A97F6A59482DCA5F46970FFB5D35031711D4AE24B7689F8A339E41B966AD84E9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038659Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.239{266C2353-0150-60AE-6802-00000000C601}11763028C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038658Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0150-60AE-6802-00000000C601}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038657Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038656Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038655Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038654Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038653Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038652Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038651Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038650Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038649Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038648Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DA-60AD-0500-00000000C601}404420C:\Windows\system32\csrss.exe{266C2353-0150-60AE-6802-00000000C601}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038647Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.022{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0150-60AE-6802-00000000C601}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038646Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.023{266C2353-0150-60AE-6802-00000000C601}1176C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038689Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.633{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0955FF3390A93C6D3C53F025556EF1FF,SHA256=70CF5F735F60CFDFAF0E4E23C0AB0049EEF2A99A4E938ABEF4C98A8A1BA2D0EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062433Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:37.293{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD465BF259BE3066732A99D19D6D281F,SHA256=7010FC93F12732AA5A3720F8D9550A80516EBD542D2F4BBA6EFB505E69863165,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038688Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0151-60AE-6A02-00000000C601}1836C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038687Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038686Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038685Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038684Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038683Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038682Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038681Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038680Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038679Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038678Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0151-60AE-6A02-00000000C601}1836C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038677Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.258{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0151-60AE-6A02-00000000C601}1836C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038676Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.259{266C2353-0151-60AE-6A02-00000000C601}1836C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038675Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.055{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6A3F9641F5AAA70CD2F585CACF872CE5,SHA256=C6B4B2E1A1A4EDFE020B9CCD685A7735CBE6DCA99912A90C8996DDA902988E45,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038674Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:37.055{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E6310626F4BEAC96F933C705ED732A52,SHA256=90BE755D3E211E2DDF0D5F75F393A84A1F98BDF502B5BE88E4BFDA834A6A1FA8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038692Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:36.375{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50571-false10.0.1.12-8000- 23542300x800000000000000038691Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:38.711{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F67FD93269A962E14B3BBA84FFAFE2E,SHA256=8BBEBAA82539B8D74CFE0BF35C395EF050645E1A5F44C5359A521355BF50FD67,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062434Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:38.308{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AF69BE7032744CE7E41E6092110F3416,SHA256=F7E0A8E37ADBD46CDD804B2F30E10613F531AAEFE95DF670CA15427B68A1C5C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038690Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:38.477{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6A3F9641F5AAA70CD2F585CACF872CE5,SHA256=C6B4B2E1A1A4EDFE020B9CCD685A7735CBE6DCA99912A90C8996DDA902988E45,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038707Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.930{266C2353-0153-60AE-6B02-00000000C601}31602812C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038706Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.790{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=80532A50697AB374D547E5DB54E258D6,SHA256=215962DF31EE03DC1237B95C57BF5C319C55F112C0F1D4A8AEFBA06ABF726B2E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062436Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:37.358{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51062-false10.0.1.12-8000- 23542300x800000000000000062435Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:39.324{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8421A697B50EC92A8F0A47036D0ECE5E,SHA256=5AB1EAA024E67D2B0EC5DC9A00613B90D4FBB0C0C259C729D2D797E34D770444,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038705Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0153-60AE-6B02-00000000C601}3160C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038704Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038703Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038702Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038701Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038700Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038699Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038698Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038697Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038696Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038695Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DA-60AD-0500-00000000C601}404980C:\Windows\system32\csrss.exe{266C2353-0153-60AE-6B02-00000000C601}3160C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038694Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.727{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0153-60AE-6B02-00000000C601}3160C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038693Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:39.728{266C2353-0153-60AE-6B02-00000000C601}3160C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038736Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.930{266C2353-0154-60AE-6D02-00000000C601}2122560C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062437Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:40.361{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C21F1C8F2D4CD094E85C59DBA96E5CFA,SHA256=5640B02EB6259BC8D78B5C088E8317ACB2E17CEE672495567AA20A073D583453,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038735Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.758{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7E8C46F65A7BEDB7028C89EBCBAA3490,SHA256=D1A2BC33EBA78B01D583232ABDCBF43BEF461C34D8EF82EDB8D4FA38BD0F4D5C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038734Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0154-60AE-6D02-00000000C601}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038733Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038732Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038731Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038730Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038729Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038728Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038727Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038726Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038725Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038724Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0154-60AE-6D02-00000000C601}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038723Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.727{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0154-60AE-6D02-00000000C601}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038722Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.728{266C2353-0154-60AE-6D02-00000000C601}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000038721Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.477{266C2353-0154-60AE-6C02-00000000C601}36282940C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038720Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0154-60AE-6C02-00000000C601}3628C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038719Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038718Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038717Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038716Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038715Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038714Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038713Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038712Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038711Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038710Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0154-60AE-6C02-00000000C601}3628C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038709Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.227{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0154-60AE-6C02-00000000C601}3628C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038708Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:40.228{266C2353-0154-60AE-6C02-00000000C601}3628C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038738Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:41.962{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FACDD6EF5E3B3D15DD09248633A688CF,SHA256=81216C32EF53DFA1CD150127A1D8AA8A0BC691CE976955CAF0C5506C930A0A55,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062446Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.635{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0155-60AE-A302-00000000C501}2260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062445Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.630{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062444Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.630{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062443Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.630{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062442Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.630{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062441Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.630{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-0155-60AE-A302-00000000C501}2260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062440Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.629{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0155-60AE-A302-00000000C501}2260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062439Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.418{7CDEDE96-0155-60AE-A302-00000000C501}2260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000062438Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:41.368{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E543D70EBAD252394B988A356789CE3C,SHA256=ECE6D02FEBFBD946BF162BCE3EA94C939B173E383852C10AF9DD96C3C4AA242F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038737Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:41.055{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD2DF91C202CB862BCE200233E8DFB85,SHA256=A272DBFBEAF8FAEC33BE0C3D2CBE42A7D708E12A31DE980E443AB2DA77F651C0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062458Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.684{7CDEDE96-0156-60AE-A402-00000000C501}6045512C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062457Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0156-60AE-A402-00000000C501}604C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062456Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062455Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062454Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-0156-60AE-A402-00000000C501}604C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062453Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062452Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062451Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.453{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0156-60AE-A402-00000000C501}604C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062450Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.300{7CDEDE96-0156-60AE-A402-00000000C501}604C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000062449Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.451{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0E245FB63ACB2500C10CCBAE48C5F244,SHA256=80D6EAF889B177A489FAC6E34007741F5A2CFCBEB8F2B06371F71DE5249F64BA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062448Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.449{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E08650D3A342B55648F5DAC1004487EC,SHA256=87F9ECD4AC222474639E9DD1CC90930FF7CF1A71259A5EC08C6FD864655F33CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062447Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:42.368{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=995898DDF96953420D05401CD0E113B0,SHA256=59297F49672B410FF77B238845E20F59CFD115BEFDDED9372BC607364D5E6906,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062468Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.894{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0157-60AE-A502-00000000C501}5396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062467Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.892{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062466Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.892{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062465Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.891{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062464Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.891{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062463Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.891{7CDEDE96-F0CE-60AD-0500-00000000C501}416532C:\Windows\system32\csrss.exe{7CDEDE96-0157-60AE-A502-00000000C501}5396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062462Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.891{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0157-60AE-A502-00000000C501}5396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062461Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.746{7CDEDE96-0157-60AE-A502-00000000C501}5396C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000062460Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.614{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\xulstore.jsonMD5=C2D6DAE75DF4370E4ECBFE8DA0771ABE,SHA256=EB5FA506C2F4AC2AFDA014ECE937534DC5E7A7750025353BBF68CA67342C30A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062459Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.383{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=73111E09D9D5F79C6B56625257EE0851,SHA256=3C28A557512623421D5169A3C81EFCDCC63EE57A9D8DFEAD4628B58263FC15C1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000038752Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DD-60AD-2B00-00000000C601}28962916C:\Windows\system32\conhost.exe{266C2353-0157-60AE-6E02-00000000C601}3624C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038751Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038750Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038749Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038748Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038747Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038746Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038745Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038744Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038743Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0C00-00000000C601}7203432C:\Windows\system32\svchost.exe{266C2353-F0DC-60AD-2200-00000000C601}1740C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000038742Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DA-60AD-0500-00000000C601}404524C:\Windows\system32\csrss.exe{266C2353-0157-60AE-6E02-00000000C601}3624C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000038741Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.339{266C2353-F0DC-60AD-2300-00000000C601}21123860C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{266C2353-0157-60AE-6E02-00000000C601}3624C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000038740Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.342{266C2353-0157-60AE-6E02-00000000C601}3624C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{266C2353-F0DA-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000038739Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:43.198{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9211936BE07D02A958F0102810E415E7,SHA256=DCAE67890EB3337158843ADA09ACA0461E1AA81E0A60B70C8429BAB98CAF3BB4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062470Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:44.758{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0E245FB63ACB2500C10CCBAE48C5F244,SHA256=80D6EAF889B177A489FAC6E34007741F5A2CFCBEB8F2B06371F71DE5249F64BA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062469Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:44.389{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C484D34753CA5E4CF7122E6DB87AC13,SHA256=13D5185BD8DA6C9D0871E861CDCF879BCBF3478A11DB2B92FEAB5DC1D3FBB0A3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038754Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:44.433{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DB33BC6EAD7C497F286133332802758,SHA256=D39F9BA225E2D6035A54E39FBD1B7C23FF439F5937210B4FFA6661FAAA69CBA0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038753Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:44.355{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9B3660E4130E4740D27F47CDD4705BED,SHA256=62B4B04D6A77FCB7F11AC5FC476CB8AFF62B463F1A02568E3201AEB1B52E22D8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062482Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-0159-60AE-A602-00000000C501}5384C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062481Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062480Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062479Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062478Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062477Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-0159-60AE-A602-00000000C501}5384C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062476Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.889{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-0159-60AE-A602-00000000C501}5384C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062475Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.729{7CDEDE96-0159-60AE-A602-00000000C501}5384C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000062474Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.276{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51064-false10.0.1.12-8000- 354300x800000000000000062473Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.108{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51063-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 354300x800000000000000062472Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:43.108{7CDEDE96-F0E1-60AD-2D00-00000000C501}2484C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-141.attackrange.local51063-true0:0:0:0:0:0:0:1win-dc-141.attackrange.local389ldap 23542300x800000000000000062471Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:45.410{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BE3CB00AD89B85D09BD5661CBF00D63,SHA256=9EA1D014F5E94D8E97AA17B69D0A43BBD47890BC4EB7864CCE246DE963CF1BEE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038756Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:45.495{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=71EC6C571DE2D1402D38372752929443,SHA256=B180455045EFFEB715F78E4315C2EB5CE98E33EE699707989675E7E9988F15CA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038755Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:42.393{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50572-false10.0.1.12-8000- 10341000x800000000000000062493Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.751{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-015A-60AE-A702-00000000C501}6024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062492Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062491Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062490Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062489Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0CE-60AD-0500-00000000C501}416432C:\Windows\system32\csrss.exe{7CDEDE96-015A-60AE-A702-00000000C501}6024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062488Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062487Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-015A-60AE-A702-00000000C501}6024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062486Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.599{7CDEDE96-015A-60AE-A702-00000000C501}6024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000062485Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.729{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5EEDB8F70F7B48AD0644C827EFC8C7D8,SHA256=CE25254F6692679DF322DDBE61ADFC0CB3C35D39A6525F1F3FEFD68DF462A5C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062484Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.414{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C32898C8C13738DDB8C5055A62DC23D,SHA256=E66809B5EB582A42FB7E6D56F6F2C6A8F5B86F4E61815FC2E30424ADE5AC4763,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038757Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:46.527{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE9CB81E9391403C3051532AFFC5C389,SHA256=03D69802466B7754E9AD7F501C72656B0D731803369545A7F3C01E8BF591A05C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062483Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:46.144{7CDEDE96-0159-60AE-A602-00000000C501}53845388C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038758Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:47.558{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C4BDD22895A75CA83D255FC95C129376,SHA256=4791BBF2F5582F5CC1E3AC53078E0B5D5BB3E4FECF28F36FF1EE6AF81CF5981D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062504Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.715{7CDEDE96-015B-60AE-A802-00000000C501}34722880C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062503Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-015B-60AE-A802-00000000C501}3472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062502Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062501Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062500Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-015B-60AE-A802-00000000C501}3472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062499Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062498Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062497Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.483{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-015B-60AE-A802-00000000C501}3472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062496Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.484{7CDEDE96-015B-60AE-A802-00000000C501}3472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000062495Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.429{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6B3DA7B2C756360FD818D9078E4881F9,SHA256=9B70DC0406B66EEBFA019DFC0B066006E936F2E0BEBAF4CA00A3C90CBDE5190C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062494Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:47.098{7CDEDE96-015A-60AE-A702-00000000C501}60242404C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038760Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:48.558{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36383F1CDE2B3691B0F7D24E5369C2AC,SHA256=EA0542F23558265774B1619C7A02D02134A5859FB2FE658674F4E63B93ED7ED1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062514Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.752{7CDEDE96-F0E2-60AD-3700-00000000C501}34003420C:\Windows\system32\conhost.exe{7CDEDE96-015C-60AE-A902-00000000C501}5224C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062513Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.750{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062512Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.750{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062511Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.750{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062510Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.750{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2800-00000000C501}2916C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062509Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.749{7CDEDE96-F0CE-60AD-0500-00000000C501}416412C:\Windows\system32\csrss.exe{7CDEDE96-015C-60AE-A902-00000000C501}5224C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000062508Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.749{7CDEDE96-F0E1-60AD-3000-00000000C501}22403476C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7CDEDE96-015C-60AE-A902-00000000C501}5224C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000062507Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.585{7CDEDE96-015C-60AE-A902-00000000C501}5224C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7CDEDE96-F0CF-60AD-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7CDEDE96-F0E1-60AD-3000-00000000C501}2240C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000062506Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.535{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1F9A08FDCCDFCEADE214245202557EE3,SHA256=43CDF3405EA847FC2D96820D033A59C0CD02766A14F55D9A1BAA67048BC357F0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062505Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.430{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4ECD8613C3354AE66ECD62BE95D34F97,SHA256=995574A9AF95701BEF52E86704E64012065DD17889976831BCDFE635BF9AB6DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038759Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:48.011{266C2353-F0DC-60AD-2300-00000000C601}2112NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2F1724F00759EE4F880E718B76065E77,SHA256=4BB0DE52B6B503EDAC96D87342AEC7B93BB8D12747B22ABA0AD4EE535930269B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038761Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:49.777{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=043EC8A546CD8427E81C801FA5F95C43,SHA256=1969615C8EEB909559DC00AA3F6B6591928124607DCA497617ED5282382ED6EC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062516Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:49.614{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F2E8270C25A40D92ED6B90380F25E851,SHA256=12AFB34A65EDBF132DCFABC01834D9A452530531475C177A36E2CEFE498BB1E4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062515Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:49.451{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=075BAA0EDCCB3EC3CDBC78A8CF765638,SHA256=ED6FFED48D12906833ABB4DB61E8350FF9112AFB2C26818A44F3E83AED45DF30,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038764Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:50.793{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B82D357B77B60759FFC7E6C6A316E3C0,SHA256=446F15C4B7295836877E3F3B55C6CCF4E46DD358BD5161F0B1CBBB5BC1036EAD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062518Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:48.386{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51065-false10.0.1.12-8000- 23542300x800000000000000062517Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.466{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCF436EA667652D92DD6FDED859850E0,SHA256=F21F7B5FD6D42C7CDF78884A31EC993C7F3B0B493F7097BFFF2FCE7D84433A51,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038763Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:48.362{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50574-false10.0.1.12-8000- 354300x800000000000000038762Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:47.127{266C2353-F0DC-60AD-2300-00000000C601}2112C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50573-false10.0.1.12-8089- 23542300x800000000000000038765Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:51.808{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F29A860F3EA08F7619C53182245525D5,SHA256=BF882DCC7B0F68B41785C873F0281B8019C460F70496C9E62E3C78C03442EFDC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062522Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:51.481{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6DE1534448837FB1A006DC6FC5B2A9DF,SHA256=3E44302E469BE52E30519D0F080E60F55574BDFD3B8A3A26595065C8E2C17A7F,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000062521Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:05:50.997{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\D370F6FF-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_D370F6FF-0000-0000-0000-100000000000.XML 13241300x800000000000000062520Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:05:50.997{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\30D2AA0C-2752-4015-BD52-B163B3999E1B\Config SourceDWORD (0x00000001) 13241300x800000000000000062519Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-SetValue2021-05-26 08:05:50.997{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\30D2AA0C-2752-4015-BD52-B163B3999E1B\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_30D2AA0C-2752-4015-BD52-B163B3999E1B.XML 23542300x800000000000000038766Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:52.824{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F77BE797C21D52505A14FCBD46246B14,SHA256=771E90DD50E1B9E44C623F7901CB7E2371E28984DF657648180176CAED0B89B8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062528Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.132{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51067-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000062527Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.131{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51067-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000062526Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.116{7CDEDE96-F0D1-60AD-0D00-00000000C501}892C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51066-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local135epmap 354300x800000000000000062525Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.116{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51066-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local135epmap 23542300x800000000000000062524Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:52.513{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B6D13E0079871AE7810DE0766A0D8D63,SHA256=E14B283C0D0A88E0BB7AEF785C4C682F768FC67DA15DAD7CA8FFC8D58F00CD29,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062523Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:52.049{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=28EC7934D540582678E072680AE8B685,SHA256=4186EE2C05C58132D432B25F87D0A32728AAC478740487C903B58DFAB3DA9762,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038767Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:53.840{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64245A74657BE6E55095DE3946E4E6AF,SHA256=114611D59288AB59907B9D1B6BB5930F54769173067A9992B096ECDE670F77C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062529Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:53.547{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4F1F410E53F76711AC31D3EB593DA1B,SHA256=B55CD5493F97FF942CE10F078B8FE2D211AC0F1827C706FA2568272214A6C210,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038768Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:54.840{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=70FDB193354A916B19EFD956BC7A271A,SHA256=4EC474E6FA04FC2699EDBCFD2C93F98AE4993BAAF408DF24C73057244D3945B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062532Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:54.564{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E1B43A50F3BCAC61EE20C9A462D17F60,SHA256=0A9A3C34BF83D91E48C20126CBBB340DF70B040F9B6B07488C9A7C07C7F00C5F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062531Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.144{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51068-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000062530Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:50.144{7CDEDE96-F0E1-60AD-2F00-00000000C501}2504C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51068-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 23542300x800000000000000038770Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:55.855{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=903535148E61F10F3AA43E0935A010E5,SHA256=110FA67D8C18AFDC5CA03FBDB7E1A86E498AC346B86AB7A2A26F9249767CD74B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062533Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:55.578{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AF6925CC0DAC65E166BB7147B856CAE1,SHA256=666032D66E27715F4181118B78DD32C59BD3F5BDF535892C7DB55C8908E80239,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038769Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:53.361{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50575-false10.0.1.12-8000- 23542300x800000000000000038771Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:56.871{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9E556BAAAE27757DFB5CCF82E6A7D6F4,SHA256=DD6608E7AF0F246D6AA5D9D0DA6D66BB769334AC6678130382AC9EE6C41002AA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062538Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.878{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-F0B3-60AD-0100-00000000C501}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 23542300x800000000000000062537Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.609{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC7139EC51A9EA00E72BA91246123800,SHA256=5603BBC63B3CE58869D3FA6DFCAC0468B01DA73B9A01B97AE390B607F50283F5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062536Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.210{7CDEDE96-F0D1-60AD-0D00-00000000C501}8926076C:\Windows\system32\svchost.exe{7CDEDE96-F8F2-60AD-8701-00000000C501}2208C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062535Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.210{7CDEDE96-F0D1-60AD-0D00-00000000C501}8926076C:\Windows\system32\svchost.exe{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062534Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.210{7CDEDE96-F0D1-60AD-0D00-00000000C501}8926076C:\Windows\system32\svchost.exe{7CDEDE96-F0E1-60AD-2B00-00000000C501}3020C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000038772Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:57.887{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AAEE33973BA14579DC7F7438CED95B8E,SHA256=CD53339646D80711A5E0D0F4295050CDC5D8C18C88E06E91E3B1710E1A716AEF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062546Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:55.891{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-141.attackrange.local51071-false10.0.1.14win-dc-141.attackrange.local389ldap 354300x800000000000000062545Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:55.891{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51071-false10.0.1.14win-dc-141.attackrange.local389ldap 354300x800000000000000062544Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:55.884{7CDEDE96-F0CF-60AD-0B00-00000000C501}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51070-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 354300x800000000000000062543Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:55.884{7CDEDE96-F0D1-60AD-1600-00000000C501}1324C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51070-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local389ldap 23542300x800000000000000062542Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:57.765{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=40B4F42BDC04B85D39A38C98137FB111,SHA256=AA4C023E6D1C49DF77A2E8BF2BADB6B121408E51EEECFAE47B6C49EA0232A579,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062541Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:57.765{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C6529C6675BFEFDA8EF8E40321AFD4E2,SHA256=9B18EB97FFC01ABC16F551448BF5F49971A6ED6AA0BC2020003624FB850F8ECC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062540Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:57.625{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FA3FA76EB65C7065E24FB4E1E9615C97,SHA256=09C99D03EB2679DC38CF5E03F164E57EBA3D873DF8DDBCF86D3FC0BB2EC1DEA0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062539Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:54.213{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51069-false10.0.1.12-8000- 23542300x800000000000000062549Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:58.650{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BB99F3EC76701B6FE6859AA07AD3A6A,SHA256=9EE67AE12B8A14E65B251FB817C6FAF804EA6433212468AF98AB95F37553DFB6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038773Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:58.903{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0F151640205BF9148F23EE171546425,SHA256=0DD529F15B8650E764F3801DBBC78A2B667E340C063998672657001AED743F64,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000062548Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.000{7CDEDE96-F0B3-60AD-0100-00000000C501}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51072-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local445microsoft-ds 354300x800000000000000062547Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:56.000{7CDEDE96-F0B3-60AD-0100-00000000C501}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local51072-truefe80:0:0:0:65f2:4cfa:8525:80c9win-dc-141.attackrange.local445microsoft-ds 23542300x800000000000000062550Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:59.698{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F377D8F7722DEB06A3BB81C197CE2BD,SHA256=718263311F9572F109B6C985ED79ED0A0AAB63690882740B83CF0CAC31194213,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038774Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:59.918{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F32C4CB9A6EAA76C347C7E662B8D3B7,SHA256=3D36CA6DDB3DFC18FCD4653AFFC7722B07660978AA52F650F658B52A47D0AF39,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038775Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:06:00.934{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2DFC30AFE49C67CD992834DD9470675,SHA256=516D1A3198E8A03D39FECBE6AA1AC1A065273F5B2C6E6F4A0C210EA136D485BD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062551Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:00.714{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=885D9DE0901B705C3376B8CC32CC10E6,SHA256=D76A77826F58746C0DBB7F2C5EC227C72F2AAC768F7BAF47A474D56E1CDD4FCF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038776Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:06:01.950{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3282D8182A3319B0C98B8C7494D1757,SHA256=623B6BF47D70787B6E12E7F49E4C3D830EF20550718562F00D72F16EB339DB19,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062552Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:01.714{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AA9C72354EB25B25FCE4B09FAA423E20,SHA256=7F98C48063F0EFE0A1F548CCDEC6B4351C73D3E9E5881AADF212C906226D8A04,IMPHASH=00000000000000000000000000000000falsetrue 11241100x800000000000000062556Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:02.982{7CDEDE96-003C-60AE-7C02-00000000C501}4140C:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\SiteSecurityServiceState.txt2021-05-25 15:18:51.260 23542300x800000000000000062555Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:02.982{7CDEDE96-003C-60AE-7C02-00000000C501}4140ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\666x5nua.default-release\SiteSecurityServiceState.txtMD5=81D6F937BD6CAC3ED404C6C583AC6747,SHA256=B8AF5D325E2ABD41BD4A3EFBAD2043C628672B70ACFDEC26620D4E8F9CA7C790,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062554Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:02.728{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B6BDE6C90A6380178DE9FAB7C9CD3620,SHA256=2910D2D8ADA35A8F810F6984F4A22BE390EDDB0405E1B1A6FD15BD335CB8C4C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000038778Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:06:02.954{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FA8220A0E6CB73F1DBA37066562EF0C,SHA256=DDC1BDFE53FF52E52000AFD3AFC28D153CBFD79A67768D2F4E383D9E97C336E5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000038777Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:05:59.299{266C2353-F0E6-60AD-6400-00000000C601}3848C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-267.attackrange.local50576-false10.0.1.12-8000- 354300x800000000000000062553Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:05:59.284{7CDEDE96-F0EC-60AD-6C00-00000000C501}3820C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-141.attackrange.local51073-false10.0.1.12-8000- 23542300x800000000000000038779Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:06:03.970{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=720DD2054748CD15D325DBA73EB5482F,SHA256=11014FE4561EC6FF74FA3902D31E4A395F5945AB036E49D5FE0590194D002C82,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062566Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:03.728{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EFD1B4962AE8B123BB8096F2310C7972,SHA256=3DE82D2D85C5229D1E4B2FB73EFEE474B5FEF78327CA47157565CDF129360BE7,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062565Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:03.397{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062564Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:03.366{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000062563Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:03.344{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5464.4.106445051C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000062562Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:06:03.344{7CDEDE96-004D-60AE-8202-00000000C501}5464\chrome.5464.4.106445051C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000062561Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:03.313{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062560Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:03.297{7CDEDE96-003C-60AE-7C02-00000000C501}41402080C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-003E-60AE-7E02-00000000C501}5700C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+2cea0|C:\Program Files\Mozilla Firefox\firefox.exe+2c9f3|C:\Program Files\Mozilla Firefox\firefox.exe+40d80|C:\Program Files\Mozilla Firefox\firefox.exe+40a7c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000062559Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:03.281{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.5464.3.81825765C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000062558Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:06:03.281{7CDEDE96-004D-60AE-8202-00000000C501}5464\chrome.5464.3.81825765C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000062557Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:03.281{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-004D-60AE-8202-00000000C501}5464C:\Program Files\Mozilla Firefox\firefox.exe0x2200C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+506f1|C:\Program Files\Mozilla Firefox\xul.dll+2a65add|C:\Program Files\Mozilla Firefox\xul.dll+2a5f4d9|C:\Program Files\Mozilla Firefox\xul.dll+2a5ffd1|C:\Program Files\Mozilla Firefox\xul.dll+2a3c000|C:\Program Files\Mozilla Firefox\xul.dll+2a3d6c4|C:\Program Files\Mozilla Firefox\xul.dll+2a40b93|C:\Program Files\Mozilla Firefox\xul.dll+1a8cbe9|C:\Program Files\Mozilla Firefox\xul.dll+1a87627|C:\Program Files\Mozilla Firefox\xul.dll+59a8a5|C:\Program Files\Mozilla Firefox\xul.dll+59a421|C:\Program Files\Mozilla Firefox\xul.dll+2f1e965|C:\Program Files\Mozilla Firefox\xul.dll+29561c|C:\Program Files\Mozilla Firefox\xul.dll+294005|C:\Program Files\Mozilla Firefox\xul.dll+1a8c460|C:\Program Files\Mozilla Firefox\xul.dll+542afa|C:\Program Files\Mozilla Firefox\xul.dll+4dadd6|C:\Program Files\Mozilla Firefox\xul.dll+d48bc1|C:\Program Files\Mozilla Firefox\xul.dll+494964|C:\Program Files\Mozilla Firefox\xul.dll+1c82aac|C:\Program Files\Mozilla Firefox\xul.dll+1611d2|C:\Program Files\Mozilla Firefox\xul.dll+108be4 23542300x800000000000000038780Microsoft-Windows-Sysmon/Operationalwin-host-267.attackrange.local-2021-05-26 08:06:04.985{266C2353-F0ED-60AD-6E00-00000000C601}4024NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8448850520D818A7149B72131BBA8524,SHA256=37743CBE681D71B32759FB32B8C135FC40FE58857B30550BADB40E8B173C9E78,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000062629Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.749{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0D50426446AEE47446B969CE19FC2DC,SHA256=0C3E04BA8C8BC5D043C4BD84A76065A768BB6052E9676F7C5233DF7F811C64CB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062628Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}41405572C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+11f6f41|C:\Program Files\Mozilla Firefox\xul.dll+1213abc|C:\Program Files\Mozilla Firefox\xul.dll+1321d41|C:\Program Files\Mozilla Firefox\xul.dll+2005b1|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+1ff2bd|C:\Program Files\Mozilla Firefox\xul.dll+40932|C:\Program Files\Mozilla Firefox\xul.dll+3f5cf|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+da69b7|C:\Program Files\Mozilla Firefox\nss3.dll+f97fa|C:\Program Files\Mozilla Firefox\nss3.dll+ecf21|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000062627Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.40.54279713C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062626Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.39.40971397C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062625Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.38.53124212C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062624Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.36.89291138C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062623Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.37.195172087C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062622Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.496{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.4140.35.166433082C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000062621Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.496{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062620Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.496{7CDEDE96-F0D1-60AD-1000-00000000C501}3841648C:\Windows\system32\svchost.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cc4|c:\windows\system32\fntcache.dll+17acf|c:\windows\system32\fntcache.dll+1a697|c:\windows\system32\fntcache.dll+1aacc|c:\windows\system32\fntcache.dll+5034e|c:\windows\system32\fntcache.dll+50052|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000062619Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.449{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.604.2.80279517C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000062618Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:06:04.449{7CDEDE96-016C-60AE-AA02-00000000C501}604\chrome.604.2.80279517C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062617Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.449{7CDEDE96-003C-60AE-7C02-00000000C501}4140\chrome.604.1.49368899C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000062616Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:06:04.449{7CDEDE96-016C-60AE-AA02-00000000C501}604\chrome.604.1.49368899C:\Program Files\Mozilla Firefox\firefox.exe 18141800x800000000000000062615Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.449{7CDEDE96-016C-60AE-AA02-00000000C501}604\chrome.604.0.202158118C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000062614Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:06:04.449{7CDEDE96-016C-60AE-AA02-00000000C501}604\chrome.604.0.202158118C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000062613Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.449{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062612Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.449{7CDEDE96-F0CF-60AD-0B00-00000000C501}6322040C:\Windows\system32\lsass.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000062611Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.445{7CDEDE96-F0F3-60AD-7500-00000000C501}3932NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F91F6E15735DEBEAAF2EEC189C0F2DE7,SHA256=C4E05315915342350A52473BC47D78B2A6FF99BF7F8D69CE4F34BF28C75FA387,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000062610Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.412{7CDEDE96-003C-60AE-7C02-00000000C501}41404704C:\Program Files\Mozilla Firefox\firefox.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+3f8761|C:\Program Files\Mozilla Firefox\xul.dll+120e14e|C:\Program Files\Mozilla Firefox\xul.dll+12af598|C:\Program Files\Mozilla Firefox\xul.dll+12270d7|C:\Program Files\Mozilla Firefox\xul.dll+12e04b9|C:\Program Files\Mozilla Firefox\xul.dll+2a4a554|C:\Program Files\Mozilla Firefox\xul.dll+12bbafb|C:\Program Files\Mozilla Firefox\xul.dll+1221814|C:\Program Files\Mozilla Firefox\xul.dll+d9aecc|C:\Program Files\Mozilla Firefox\xul.dll+40c6e|C:\Program Files\Mozilla Firefox\xul.dll+1224b30|C:\Program Files\Mozilla Firefox\xul.dll+11fca9f|C:\Program Files\Mozilla Firefox\xul.dll+3f49e|C:\Program Files\Mozilla Firefox\xul.dll+3d19c8|C:\Program Files\Mozilla Firefox\xul.dll+3d073f|C:\Program Files\Mozilla Firefox\xul.dll+3a1d1aa|C:\Program Files\Mozilla Firefox\xul.dll+3aba26f|C:\Program Files\Mozilla Firefox\xul.dll+3abb5e9|C:\Program Files\Mozilla Firefox\xul.dll+3f33|C:\Program Files\Mozilla Firefox\firefox.exe+1594|C:\Program Files\Mozilla Firefox\firefox.exe+4c4e8|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000062609Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-ConnectPipe2021-05-26 08:06:04.412{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-4C:\Program Files\Mozilla Firefox\firefox.exe 17141700x800000000000000062608Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-CreatePipe2021-05-26 08:06:04.412{7CDEDE96-003C-60AE-7C02-00000000C501}4140\cubeb-pipe-4140-4C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000062607Microsoft-Windows-Sysmon/Operationalwin-dc-141.attackrange.local-2021-05-26 08:06:04.412{7CDEDE96-F0D0-60AD-0C00-00000000C501}8364184C:\Windows\system32\svchost.exe{7CDEDE96-016C-60AE-AA02-00000000C501}604C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000062606