23542300x800000000000000084662Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:37.599{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=825264531ADF3F97E002805F27E10C19,SHA256=CEBDE74F5CAAEC0181FAC50CA8A7334C3E3BD568E9466934B33B412EE02A744E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117037Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:37.037{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0392DA4BD8194BE4922157F1AC6AAED2,SHA256=CA896EA48CF8C3FC070CC83353C4D4613712483E8EF5A85E22079360614CBF64,IMPHASH=00000000000000000000000000000000falsetrue
354300x800000000000000084661Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:34.660{9531C931-287C-623C-6A00-000000004302}3024C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-tcontreras-attack-range-971.eu-central-1.compute.internal51605-false10.0.1.12-8000-
23542300x800000000000000084663Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:38.693{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FB62870037A775AE9DF0552E3898233F,SHA256=491300AFDA429792CAE30A88CA7FA0D081B0A4DD42BBAF4C3DFB140A0C62A163,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117038Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:38.130{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A9B18DB348AD54459E0A6502CBCEE47,SHA256=1936DCB533A52ED56A624005DD0F74652AF0F39151333F97B33118ED9B7D14A4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084665Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:39.943{9531C931-286D-623C-1200-000000004302}968NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=178BD93BA824959F2442BC7DE30AC3FA,SHA256=5EFF056003DC3EB000EEECA8F4C5E9845950167AF08BE5D701F6822654968F6C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084664Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:39.786{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E7C078EC5827203FFC63E310F15FED5,SHA256=5EB5FAA6D38111A40161A7894197D764D49165823BE6D77E239C303A31A5ED3F,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000117041Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:37.785{5F3DCEF0-2886-623C-7800-000000004202}3396C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-tcontreras-attack-range-891.attackrange.local63202-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000-
23542300x8000000000000000117040Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:39.224{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C556EA052DB4FF6FED7D88B47C6716CD,SHA256=373B98C1932C592F7132EF50BF2DE26FAD7598A49F66728A293E864EF0FC4422,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117039Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:39.115{5F3DCEF0-286D-623C-1300-000000004202}488NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=6EE838195D2D1849D53718D493474C86,SHA256=8FEE58AFD01E013FA3536EB9F52DEBE049E186CCE85AB1B3E5124245FFAA40E3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084666Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:40.880{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F888D0F186DDCAFAC8B364958BA9E1EE,SHA256=57F0B23B2E52FEF4B7173761CB0043600F45AE7EA8C2465212724A1ED3107F3E,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000117286Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117285Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117284Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117283Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117282Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117281Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117280Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117279Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117278Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117277Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117276Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117275Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117274Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117273Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117272Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117271Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117270Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117269Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117268Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117267Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117266Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117265Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117264Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117263Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117262Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117261Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117260Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117259Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117258Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117257Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117256Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117255Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117254Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117253Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117252Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117251Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117250Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117249Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117248Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117247Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117246Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117245Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117244Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117243Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117242Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117241Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117240Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117239Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117238Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117237Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117236Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117235Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117234Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117233Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117232Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117231Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117230Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117229Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117228Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117227Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117226Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117225Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117224Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117223Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117222Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117221Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117220Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117219Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117218Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117217Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117216Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117215Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117214Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117213Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117212Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117211Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117210Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117209Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117208Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117207Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117206Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117205Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117204Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117203Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117202Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117201Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117200Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117199Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117198Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117197Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117196Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117195Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117194Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117193Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117192Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117191Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117190Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117189Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117188Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117187Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117186Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117185Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117184Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117183Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117182Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117181Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117180Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117179Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117178Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117177Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117176Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117175Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117174Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117173Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117172Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117171Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117170Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117169Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117168Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117167Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117166Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117165Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117164Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117163Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117162Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117161Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117160Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117159Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117158Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117157Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117156Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117155Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117154Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117153Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117152Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117151Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117150Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117149Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117148Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117147Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117146Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117145Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E68-623C-6805-000000004202}6796C:\Windows\system32\findstr.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117144Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117143Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117142Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117141Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E50-623C-6405-000000004202}6544C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117140Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E50-623C-6305-000000004202}6104C:\Windows\system32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117139Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-43D6-623C-FF03-000000004202}3712C:\Windows\system32\mspaint.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117138Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4362-623C-F003-000000004202}4208C:\Windows\system32\mspaint.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117137Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4350-623C-EE03-000000004202}2816C:\Windows\system32\mspaint.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117136Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117135Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117134Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2A2F-623C-ED00-000000004202}2436C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117133Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117132Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117131Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117130Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117129Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117128Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117127Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117126Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28F5-623C-AE00-000000004202}5884C:\Windows\System32\msdtc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117125Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117124Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117123Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28AE-623C-9E00-000000004202}5732C:\Program Files\Greenshot\Greenshot.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117122Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117121Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117120Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117119Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117118Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A3-623C-9800-000000004202}5168C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117117Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A3-623C-9700-000000004202}4748C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117116Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A1-623C-9400-000000004202}5024C:\Windows\Explorer.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117115Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A1-623C-8E00-000000004202}4668C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117114Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A1-623C-8B00-000000004202}4584C:\Windows\System32\rdpclip.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117113Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-289F-623C-8800-000000004202}4188C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117112Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-289E-623C-8600-000000004202}3292C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117111Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-288D-623C-8200-000000004202}3916C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117110Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2886-623C-7800-000000004202}3396C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117109Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287D-623C-4F00-000000004202}3752C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117108Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287D-623C-4A00-000000004202}3652C:\Program Files\Amazon\SSM\ssm-agent-worker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117107Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287C-623C-4300-000000004202}3448C:\Windows\System32\vds.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117106Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117105Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117104Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117103Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287C-623C-3C00-000000004202}3284C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117102Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117101Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117100Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117099Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3800-000000004202}2256C:\Windows\system32\wbem\unsecapp.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117098Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.802{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117097Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117096Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117095Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117094Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117093Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3700-000000004202}2600C:\Windows\system32\dfssvc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117092Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117091Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117090Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117089Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117088Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117087Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3500-000000004202}2112C:\Windows\system32\DFSRs.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117086Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3400-000000004202}2020C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117085Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3300-000000004202}2336C:\Windows\System32\ismserv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117084Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3200-000000004202}2344C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117083Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3000-000000004202}1396C:\Windows\system32\dns.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117082Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-2F00-000000004202}3064C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117081Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-2E00-000000004202}3044C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117080Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-2C00-000000004202}2972C:\Windows\System32\spoolsv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117079Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2876-623C-2A00-000000004202}2808C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117078Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2874-623C-2900-000000004202}2732C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117077Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2874-623C-2800-000000004202}2724C:\Users\Public\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117076Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286E-623C-2100-000000004202}2144C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117075Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1700-000000004202}1400C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117074Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1600-000000004202}1260C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117073Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1500-000000004202}1220C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117072Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1400-000000004202}1088C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117071Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1300-000000004202}488C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117070Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1200-000000004202}396C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117069Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1100-000000004202}408C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117068Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1000-000000004202}428C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117067Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.787{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-0F00-000000004202}100C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117066Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.771{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-0E00-000000004202}980C:\Windows\system32\LogonUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117065Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.771{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-0D00-000000004202}884C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117064Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.771{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286C-623C-0C00-000000004202}824C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117063Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.771{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286B-623C-0B00-000000004202}620C:\Windows\system32\lsass.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117062Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.771{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286A-623C-0900-000000004202}560C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117061Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.771{5F3DCEF0-286B-623C-0B00-000000004202}620816C:\Windows\system32\lsass.exe{5F3DCEF0-4E57-623C-6605-000000004202}6804C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6b44|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117060Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.755{5F3DCEF0-286B-623C-0B00-000000004202}620816C:\Windows\system32\lsass.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6b44|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117059Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.740{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+40856|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\RPCRT4.dll+52caa|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117058Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.740{5F3DCEF0-4E50-623C-6405-000000004202}65446556C:\Windows\system32\conhost.exe{5F3DCEF0-4E68-623C-6805-000000004202}6796C:\Windows\system32\findstr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117057Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117056Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117055Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117054Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117053Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-289E-623C-8500-000000004202}29804996C:\Windows\system32\csrss.exe{5F3DCEF0-4E68-623C-6805-000000004202}6796C:\Windows\system32\findstr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f
10341000x8000000000000000117052Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-4E50-623C-6305-000000004202}61046536C:\Windows\system32\cmd.exe{5F3DCEF0-4E68-623C-6805-000000004202}6796C:\Windows\system32\findstr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b346|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+c3f6|C:\Windows\system32\cmd.exe+4917|C:\Windows\system32\cmd.exe+c378|C:\Windows\system32\cmd.exe+1ace3|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
154100x8000000000000000117051Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.735{5F3DCEF0-4E68-623C-6805-000000004202}6796C:\Windows\System32\findstr.exe10.0.14393.0 (rs1_release.160715-1616)Find String (QGREP) UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationFINDSTR.EXEfindstr doublezeroC:\Users\Administrator\ATTACKRANGE\Administrator{5F3DCEF0-28A0-623C-DB99-080000000000}0x899db2HighMD5=15B171EC73E7B71F4EBB4247E716271E,SHA256=2956F7BC863498DFCC868CE7DF4C9C131A4A5C17B065658456AFEF7566ACE1EE,IMPHASH=D7962312082AAB17974D6817E09E5D7A{5F3DCEF0-4E50-623C-6305-000000004202}6104C:\Windows\System32\cmd.exe"C:\Windows\system32\cmd.exe"
10341000x8000000000000000117050Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-4E50-623C-6405-000000004202}65446556C:\Windows\system32\conhost.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117049Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117048Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117047Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117046Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117045Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-289E-623C-8500-000000004202}29804132C:\Windows\system32\csrss.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f
10341000x8000000000000000117044Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.724{5F3DCEF0-4E50-623C-6305-000000004202}61046536C:\Windows\system32\cmd.exe{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\system32\tasklist.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b346|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+c3f6|C:\Windows\system32\cmd.exe+484b|C:\Windows\system32\cmd.exe+c378|C:\Windows\system32\cmd.exe+1ace3|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
154100x8000000000000000117043Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.732{5F3DCEF0-4E68-623C-6705-000000004202}6488C:\Windows\System32\tasklist.exe10.0.14393.0 (rs1_release.160715-1616)Lists the current running tasksMicrosoft® Windows® Operating SystemMicrosoft Corporationtasklist.exetasklist C:\Users\Administrator\ATTACKRANGE\Administrator{5F3DCEF0-28A0-623C-DB99-080000000000}0x899db2HighMD5=6F2FDCF651A1650FC7B4FC5A860E4D9D,SHA256=27EDDAC6A2E5A74DF67C534393B0B025B03D61310748BE016DCE348A02D30A22,IMPHASH=9C5CFDDF3336412B8046D54234415205{5F3DCEF0-4E50-623C-6305-000000004202}6104C:\Windows\System32\cmd.exe"C:\Windows\system32\cmd.exe"
23542300x8000000000000000117042Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:40.318{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=351CC7211BB25CA987E4C288DA5D595F,SHA256=CCC861228D12678D4A2D1B917A00A086B5E1729FB44B3CC1EFEC67AA086D2ECE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084668Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:41.978{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=72766B0E17AAA75610DBBDB6EA611C41,SHA256=C5FDB85EF6763789823C0A3168738BE3BB4FF478A5D17088B8E3E4BEA9385BBC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117290Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:41.802{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6004C071518401D59B5302D8EB33A393,SHA256=6D387E1013F19FA2CF590F1C08883ABEF913195EF3C582C18E041848C17819EF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117289Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:41.630{5F3DCEF0-287B-623C-3200-000000004202}2344NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=2B25FDCC12974A9C381F03B139373D5A,SHA256=CCB13157BCC6FA0284F12C6446F2447FFDD0F4F85F98465868293CDAEA96B09E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117288Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:41.521{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A8B06529DE72772A4A210ABB67376204,SHA256=0019ABD3EEBF6CCF8DE9EFE4A1A0518A33AB11BF2C7A0663A43E9BF2EFC962F9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117287Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:41.505{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=60DAEAD3868CD1D3F1ABF3D4409FBBAD,SHA256=E6D33F4E74D0F8934960A6EB202DDF3BB82584845E7F04CB993C20DE0787A9E5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084667Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:41.871{9531C931-286E-623C-1F00-000000004302}1932NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0461bb3aaa367e86a\channels\health\respondent-20220324081441-157MD5=E0BA989DE2EAC2D304FA728EF5181BE5,SHA256=79811ABCB3575FCAAAD7A2ED1966FC2D319842A68AFDD7DF3600AD47FF32DF65,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000117536Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:41.379{5F3DCEF0-287B-623C-3200-000000004202}2344C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-tcontreras-attack-range-891.attackrange.local63203-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089-
10341000x8000000000000000117535Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117534Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117533Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117532Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117531Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117530Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117529Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117528Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117527Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117526Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117525Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117524Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117523Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117522Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117521Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117520Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117519Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117518Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117517Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117516Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.912{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117515Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117514Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117513Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117512Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117511Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117510Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117509Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117508Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117507Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
23542300x800000000000000084672Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:42.869{9531C931-286E-623C-1F00-000000004302}1932NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0461bb3aaa367e86a\channels\health\surveyor-20220324081439-158MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue
10341000x800000000000000084671Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:42.181{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-1300-000000004302}700C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084670Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:42.181{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-1300-000000004302}700C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084669Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:42.181{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-1300-000000004302}700C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117506Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117505Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117504Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117503Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117502Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117501Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117500Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117499Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117498Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117497Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117496Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117495Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.896{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117494Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117493Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117492Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117491Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117490Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|c:\windows\system32\lsm.dll+1cd9|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117489Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1c24|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117488Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117487Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117486Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117485Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117484Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117483Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117482Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117481Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117480Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117479Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117478Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117477Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117476Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117475Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117474Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117473Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117472Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117471Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117470Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117469Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117468Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117467Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117466Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117465Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117464Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117463Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117462Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117461Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117460Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117459Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117458Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117457Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117456Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117455Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117454Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117453Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.880{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117452Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117451Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117450Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117449Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117448Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117447Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117446Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117445Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117444Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117443Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117442Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117441Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117440Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117439Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117438Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117437Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117436Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117435Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117434Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117433Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117432Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117431Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117430Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117429Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117428Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117427Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117426Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117425Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117424Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117423Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.865{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117422Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117421Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117420Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117419Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117418Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117417Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117416Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117415Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117414Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117413Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117412Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117411Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117410Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117409Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117408Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117407Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117406Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117405Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117404Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117403Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117402Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117401Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117400Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117399Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117398Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117397Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117396Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117395Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117394Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117393Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.849{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117392Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E6A-623C-6A05-000000004202}2680C:\Windows\system32\findstr.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117391Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117390Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E50-623C-6405-000000004202}6544C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117389Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4E50-623C-6305-000000004202}6104C:\Windows\system32\cmd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117388Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117387Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117386Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117385Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-43D6-623C-FF03-000000004202}3712C:\Windows\system32\mspaint.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117384Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117383Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117382Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117381Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4362-623C-F003-000000004202}4208C:\Windows\system32\mspaint.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117380Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117379Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-4350-623C-EE03-000000004202}2816C:\Windows\system32\mspaint.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117378Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117377Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117376Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117375Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117374Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2A2F-623C-ED00-000000004202}2436C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117373Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117372Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117371Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117370Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28F5-623C-AE00-000000004202}5884C:\Windows\System32\msdtc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117369Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117368Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28AE-623C-9E00-000000004202}5732C:\Program Files\Greenshot\Greenshot.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117367Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A3-623C-9800-000000004202}5168C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117366Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A3-623C-9700-000000004202}4748C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117365Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A1-623C-9400-000000004202}5024C:\Windows\Explorer.EXE0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117364Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A1-623C-8E00-000000004202}4668C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117363Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-28A1-623C-8B00-000000004202}4584C:\Windows\System32\rdpclip.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117362Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-289F-623C-8800-000000004202}4188C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117361Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-289E-623C-8600-000000004202}3292C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117360Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-288D-623C-8200-000000004202}3916C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117359Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2886-623C-7800-000000004202}3396C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117358Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117357Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117356Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117355Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117354Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287D-623C-4F00-000000004202}3752C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117353Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117352Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117351Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117350Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117349Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287D-623C-4A00-000000004202}3652C:\Program Files\Amazon\SSM\ssm-agent-worker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117348Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117347Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117346Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.833{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117345Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287C-623C-4300-000000004202}3448C:\Windows\System32\vds.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117344Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117343Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287C-623C-3C00-000000004202}3284C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117342Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117341Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3800-000000004202}2256C:\Windows\system32\wbem\unsecapp.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117340Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3700-000000004202}2600C:\Windows\system32\dfssvc.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117339Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117338Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117337Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117336Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3500-000000004202}2112C:\Windows\system32\DFSRs.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117335Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3400-000000004202}2020C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117334Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3300-000000004202}2336C:\Windows\System32\ismserv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117333Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3200-000000004202}2344C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117332Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-3000-000000004202}1396C:\Windows\system32\dns.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117331Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-2F00-000000004202}3064C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117330Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-2E00-000000004202}3044C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117329Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-287B-623C-2C00-000000004202}2972C:\Windows\System32\spoolsv.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117328Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2876-623C-2A00-000000004202}2808C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117327Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2874-623C-2900-000000004202}2732C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117326Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-2874-623C-2800-000000004202}2724C:\Users\Public\splunkd.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117325Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286E-623C-2100-000000004202}2144C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117324Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1700-000000004202}1400C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117323Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1600-000000004202}1260C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117322Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1500-000000004202}1220C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117321Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1400-000000004202}1088C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117320Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1300-000000004202}488C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117319Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1200-000000004202}396C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117318Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1100-000000004202}408C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117317Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-1000-000000004202}428C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117316Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-0F00-000000004202}100C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117315Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-0E00-000000004202}980C:\Windows\system32\LogonUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117314Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286D-623C-0D00-000000004202}884C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117313Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286C-623C-0C00-000000004202}824C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117312Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286B-623C-0B00-000000004202}620C:\Windows\system32\lsass.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117311Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.818{5F3DCEF0-4E57-623C-6605-000000004202}68046240C:\Windows\system32\wbem\wmiprvse.exe{5F3DCEF0-286A-623C-0900-000000004202}560C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\cimwin32.dll+6fb3|C:\Windows\system32\wbem\cimwin32.dll+7471|C:\Windows\SYSTEM32\framedynos.dll+5899|C:\Windows\SYSTEM32\framedynos.dll+adc4|C:\Windows\system32\wbem\wmiprvse.exe+a731|C:\Windows\system32\wbem\wmiprvse.exe+a344|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\combase.dll+12d0|C:\Windows\System32\RPCRT4.dll+6518b|C:\Windows\System32\combase.dll+3b20c|C:\Windows\System32\combase.dll+3aec2|C:\Windows\System32\combase.dll+39768|C:\Windows\System32\combase.dll+3755d|C:\Windows\System32\combase.dll+36c2f|C:\Windows\System32\combase.dll+52149|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3530e|C:\Windows\System32\RPCRT4.dll+20c87|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c
10341000x8000000000000000117310Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.802{5F3DCEF0-286B-623C-0B00-000000004202}620816C:\Windows\system32\lsass.exe{5F3DCEF0-4E57-623C-6605-000000004202}6804C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6b44|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117309Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.802{5F3DCEF0-286B-623C-0B00-000000004202}620816C:\Windows\system32\lsass.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6b44|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117308Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.787{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+40856|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+545cb|C:\Windows\System32\RPCRT4.dll+52caa|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117307Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117306Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-4E50-623C-6405-000000004202}65446556C:\Windows\system32\conhost.exe{5F3DCEF0-4E6A-623C-6A05-000000004202}2680C:\Windows\system32\findstr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117305Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117304Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117303Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117302Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-4E50-623C-6405-000000004202}65446556C:\Windows\system32\conhost.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117301Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-289E-623C-8500-000000004202}29806004C:\Windows\system32\csrss.exe{5F3DCEF0-4E6A-623C-6A05-000000004202}2680C:\Windows\system32\findstr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f
10341000x8000000000000000117300Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-4E50-623C-6305-000000004202}61046536C:\Windows\system32\cmd.exe{5F3DCEF0-4E6A-623C-6A05-000000004202}2680C:\Windows\system32\findstr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b346|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+c3f6|C:\Windows\system32\cmd.exe+4917|C:\Windows\system32\cmd.exe+c378|C:\Windows\system32\cmd.exe+1ace3|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
154100x8000000000000000117299Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.780{5F3DCEF0-4E6A-623C-6A05-000000004202}2680C:\Windows\System32\findstr.exe10.0.14393.0 (rs1_release.160715-1616)Find String (QGREP) UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationFINDSTR.EXEfindstr doublezero.exeC:\Users\Administrator\ATTACKRANGE\Administrator{5F3DCEF0-28A0-623C-DB99-080000000000}0x899db2HighMD5=15B171EC73E7B71F4EBB4247E716271E,SHA256=2956F7BC863498DFCC868CE7DF4C9C131A4A5C17B065658456AFEF7566ACE1EE,IMPHASH=D7962312082AAB17974D6817E09E5D7A{5F3DCEF0-4E50-623C-6305-000000004202}6104C:\Windows\System32\cmd.exe"C:\Windows\system32\cmd.exe"
10341000x8000000000000000117298Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117297Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117296Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117295Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-286C-623C-0C00-000000004202}8246244C:\Windows\system32\svchost.exe{5F3DCEF0-287B-623C-3600-000000004202}2384C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117294Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-289E-623C-8500-000000004202}29802452C:\Windows\system32\csrss.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f
10341000x8000000000000000117293Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.771{5F3DCEF0-4E50-623C-6305-000000004202}61046536C:\Windows\system32\cmd.exe{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\system32\tasklist.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b346|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+c3f6|C:\Windows\system32\cmd.exe+484b|C:\Windows\system32\cmd.exe+c378|C:\Windows\system32\cmd.exe+1ace3|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
154100x8000000000000000117292Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.779{5F3DCEF0-4E6A-623C-6905-000000004202}6440C:\Windows\System32\tasklist.exe10.0.14393.0 (rs1_release.160715-1616)Lists the current running tasksMicrosoft® Windows® Operating SystemMicrosoft Corporationtasklist.exetasklist C:\Users\Administrator\ATTACKRANGE\Administrator{5F3DCEF0-28A0-623C-DB99-080000000000}0x899db2HighMD5=6F2FDCF651A1650FC7B4FC5A860E4D9D,SHA256=27EDDAC6A2E5A74DF67C534393B0B025B03D61310748BE016DCE348A02D30A22,IMPHASH=9C5CFDDF3336412B8046D54234415205{5F3DCEF0-4E50-623C-6305-000000004202}6104C:\Windows\System32\cmd.exe"C:\Windows\system32\cmd.exe"
23542300x8000000000000000117291Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:42.615{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=127D82F38D38E63DB701D58B89415E5F,SHA256=F2C9311F7241F815D044590F35E67826C9B6717892AD1D681D475E0A5AA31658,IMPHASH=00000000000000000000000000000000falsetrue
354300x800000000000000084674Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:40.600{9531C931-287C-623C-6A00-000000004302}3024C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-tcontreras-attack-range-971.eu-central-1.compute.internal51606-false10.0.1.12-8000-
23542300x800000000000000084673Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:43.072{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3BC9A01D0133CF09004A40C6412B1E1,SHA256=78854DD5F3920938DC88B9D4C1B7350B706FD554C639CF3BE9DA6598DC68E451,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117538Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:43.037{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B672D4FD1138B4E07772DD5E44722A24,SHA256=C2358DA3072911F5AB0A49D2F3900441C9CBF79DD56CF9430678F52528968FCC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117537Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:43.021{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B1147377BEC0D36BA2E70FF2BFDFA646,SHA256=51C09F0D83A6AEFEB514CA1234BD305FA1CF58FB2F0178544B562EBA750124C5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084675Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:44.167{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0C8E72EEF224ED18044EA214D46E8DD,SHA256=F7C5C687AB1495F6B2BEA484B9D35856BDB04659965F9325397D7E72300F52DC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117539Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:44.177{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8FC01DE89B1D0F93D5963F369809BB75,SHA256=36D91318A746873EC77F230ACE79B7B5287002D0BB5A8ADC881E098A3D320ABC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084676Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:45.261{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21F12B292659C5FFCDC12D023C870F9F,SHA256=BE192A00C538ECE6A8FA62BF1A9F28CEF99089943DC0E13F18A63B7B3F6C6820,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117540Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:45.224{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA90B1DF3534DDCA199947660A648DC2,SHA256=28487393654A75BC697F231B97B533572A90C04DD6A2FAF516FDB979462D8A6F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084677Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:46.354{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE26E0C2A04982DBC71FC4B09EDD6E0D,SHA256=80A2E2F7F93BF92C963B2A581942AD1F1C98300320E5327A7A67459316DB3DB3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117542Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:46.318{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=80699CA0C62E541349FB245889B22E92,SHA256=34ED07719E63489F38EF02B9AB11E0DD04806DEB73D0017567B6530401FC3BD8,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000117541Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:43.832{5F3DCEF0-2886-623C-7800-000000004202}3396C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-tcontreras-attack-range-891.attackrange.local63204-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000-
23542300x800000000000000084678Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:47.448{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD7F3382D0DAFD642266F0C4B87D96C9,SHA256=28C97E26E8EEB9921C3556E35BF1B2DA3433FAE265AFF39A08F5A91FDED3EE09,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117543Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:47.412{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=209794C9CF56254BAF7F60319D955E92,SHA256=091097B512E1CC1058F5936BFCC68C53F7F50C267BCF5DC90872CCB908AB92DF,IMPHASH=00000000000000000000000000000000falsetrue
354300x800000000000000084680Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:45.605{9531C931-287C-623C-6A00-000000004302}3024C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-tcontreras-attack-range-971.eu-central-1.compute.internal51607-false10.0.1.12-8000-
23542300x800000000000000084679Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:48.542{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=682B2C11EDEBCE89620580AA4AF40120,SHA256=DE8BFCADAECEBD79C0A8F7D69B2874E16AD6F932D6A04DF2D5505D8573E72A0C,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000117546Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:48.833{5F3DCEF0-286B-623C-0B00-000000004202}620816C:\Windows\system32\lsass.exe{5F3DCEF0-28A1-623C-9400-000000004202}5024C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6b44|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x8000000000000000117545Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:48.833{5F3DCEF0-286B-623C-0B00-000000004202}620816C:\Windows\system32\lsass.exe{5F3DCEF0-28A1-623C-9400-000000004202}5024C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\lsasrv.dll+6ea9c|C:\Windows\system32\lsasrv.dll+e6b44|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
23542300x8000000000000000117544Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:48.505{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0050F1AB3078946470330EDF800807A,SHA256=0E54C257C865793721312999DBE60A6CA9F1F4A8BE96820E263D509B2B977FDE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084681Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:49.636{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E533297A995F40F63C608581B48CFF7,SHA256=8713DC098A63B8AC04C737FBA4F20B153E3A971B63F6413C08945E5BEEDF37A8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117547Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:49.599{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=450AD666E26928601B499FF37C563248,SHA256=FCD1F05DAD8A29F5D81D42DBBCC93B106A061F0477CAAF543FBF00F7AACC29FE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084682Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:50.729{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E6ABFC3520A6DB82A6CA0C3E9411F57E,SHA256=1F09D668F70C9D8C5A464575A2408E000DA7C24C46A7BFEBD3AB68F77B8C0C66,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117548Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:50.693{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EFF9F0A2C3E6D740668AEEB6B42A307C,SHA256=059321CD92394E52F74FB669EF169D6DD8B8C81D5AB1168A617CB9A0745028C8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x800000000000000084683Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:51.823{9531C931-2883-623C-7B00-000000004302}3236NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=42B24FDEF21C8975BA775172AC9C1970,SHA256=8AAA6BAD772D2962F7C9DB6AF8C43A003A7EC2291DFA718AD947B31F01363D8C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000117550Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:51.787{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4030D88003C9FCAB4066A9F06FE4F8A0,SHA256=B3252F2320C04FC27419AB82DF485C1B4F90C6523F7EA0320B027F147A216009,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000117549Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:49.863{5F3DCEF0-2886-623C-7800-000000004202}3396C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-tcontreras-attack-range-891.attackrange.local63205-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000-
10341000x800000000000000084710Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.948{9531C931-4E74-623C-FE04-000000004302}4163996C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{9531C931-286E-623C-2100-000000004302}2000C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6ae795|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6ae2c6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+643d8|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+65dfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+9dcf50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
23542300x8000000000000000117551Microsoft-Windows-Sysmon/Operationalwin-dc-tcontreras-attack-range-891.attackrange.local-2022-03-24 10:56:52.990{5F3DCEF0-288D-623C-8200-000000004202}3916NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=777E528C8A05B95BE9355AA10B403306,SHA256=B84C0829749A8B6E2CF47E43988F0E837ADD572073806CDCF61B762A6E0B8B4F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x800000000000000084709Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-2870-623C-2D00-000000004302}28322852C:\Windows\system32\conhost.exe{9531C931-4E74-623C-FE04-000000004302}416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084708Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084707Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084706Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084705Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084704Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084703Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084702Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084701Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084700Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084699Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286C-623C-0500-000000004302}4081060C:\Windows\system32\csrss.exe{9531C931-4E74-623C-FE04-000000004302}416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f
10341000x800000000000000084698Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.729{9531C931-286E-623C-2100-000000004302}20003200C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{9531C931-4E74-623C-FE04-000000004302}416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b346|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e499f1|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+1b3255|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+1bd30d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+1b59b6|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+dd3c14|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+1bd79a|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+1c0f1c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+dd07d2|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+dd491d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+1bb965|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+dc694e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
154100x800000000000000084697Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.730{9531C931-4E74-623C-FE04-000000004302}416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.2.5Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{9531C931-286D-623C-E703-000000000000}0x3e70SystemMD5=611F936426EC989CDC9FB43B692D3CFA,SHA256=AF94FF9B82C4BF6F27A5695E741D2BDF06A6A574924179D0BC9E7B8A725882F5,IMPHASH=A2763C4BA6D4717F662584401724A6B2{9531C931-286E-623C-2100-000000004302}2000C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x800000000000000084696Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-2870-623C-2D00-000000004302}28322852C:\Windows\system32\conhost.exe{9531C931-4E74-623C-FD04-000000004302}3364C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084695Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084694Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084693Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084692Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084691Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
10341000x800000000000000084690Microsoft-Windows-Sysmon/Operationalwin-host-tcontreras-attack-range-971-2022-03-24 10:56:52.229{9531C931-286D-623C-0C00-000000004302}720328C:\Windows\system32\svchost.exe{9531C931-286E-623C-2500-000000004302}1436C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a523|C:\Windows\System32\RPCRT4.dll+d5bc1|C:\Windows\System32\RPCRT4.dll+52cfc|C:\Windows\System32\RPCRT4.dll+358a4|C:\Windows\System32\RPCRT4.dll+347bd|C:\Windows\System32\RPCRT4.dll+3506b|C:\Windows\System32\RPCRT4.dll+20e5c|C:\Windows\System32\RPCRT4.dll+212dc|C:\Windows\System32\RPCRT4.dll+1049c|C:\Windows\System32\RPCRT4.dll+11cfb|C:\Windows\System32\RPCRT4.dll+1a58a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791
1034100