23542300x800000000000000025301Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:31.704{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ABE12F8D0BA7C5986472597AAE9CBF44,SHA256=EC73B6986DD86666E3A088B3DCD996E6395CAAA6CDED8358270133F85E6EFB8B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047117Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.838{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047116Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.838{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047115Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.837{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047114Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.837{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047113Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.837{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047112Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.836{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047111Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.836{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000047110Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:31.800{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6811844916430964287C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047109Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:31.800{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6811844916430964287C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047108Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.777{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047107Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:31.777{C8F4C507-6257-6140-DD08-00000000F001}6364\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047106Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:31.773{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6194272261485191427C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047105Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:31.773{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6194272261485191427C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047104Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:31.764{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17404060153776191793C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047103Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:31.764{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17404060153776191793C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047102Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.752{C8F4C507-5C83-6140-A007-00000000F001}42241076C:\Windows\system32\csrss.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047101Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.752{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6257-6140-DD08-00000000F001}6364C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047100Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:31.750{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.8490014228683262187C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047099Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:31.750{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.8490014228683262187C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047098Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.729{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84378D1B8CD4A451FC7FCAC91D6B2480,SHA256=1CC0F820294C038885DCF247841FAADFF2623D37C5B288A7B64022173019606F,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047097Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.930{C8F4C507-61CB-6140-9408-00000000F001}4428content-autofill.googleapis.com0142.250.181.234;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047096Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.851{C8F4C507-61CB-6140-9408-00000000F001}4428apis.google.com0type: 5 plus.l.google.com;142.250.181.238;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047095Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.432{C8F4C507-61CB-6140-9408-00000000F001}4428consent.youtube.com0142.250.186.174;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047094Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.257{C8F4C507-61CB-6140-9408-00000000F001}4428consent.google.de0172.217.16.142;C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047093Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:30.171{C8F4C507-4953-6140-6D00-00000000F001}3440C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local50150-false10.0.1.12-8000- 354300x800000000000000047092Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.998{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50149-false142.250.185.98fra16s49-in-f2.1e100.net443https 354300x800000000000000047091Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.995{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59817- 354300x800000000000000047090Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.925{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61185-false142.250.181.234fra16s56-in-f10.1e100.net443https 354300x800000000000000047089Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:29.850{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local58551-false142.250.181.238fra16s56-in-f14.1e100.net443https 23542300x800000000000000025303Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:32.845{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=972F0BA416224E20BDE17C62EA538395,SHA256=C329672516054C4D76CCB3F94F5FE617AF9A2C71D84B4C05C52A4008B047933C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047138Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.817{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=69DB7B2AEEDC3460F278635E61C63831,SHA256=C9D41CFB3583EC5AD1429E77E3ADFFE99786FEA0A6E87AB6E5D53A373D302862,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047137Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.807{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=435311C5A02BD920B4483A5D0867CE32,SHA256=FBBBE6EF52DAC1B875C7E41EC1253F5FBC88FC3447A2E433CF308CC2E7E6059F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047136Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.807{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=17C3AAD787D66CEC35AE2D725CA8787A,SHA256=DC33D09BBAD23FD3D1659B9D1DD3B5A33F759D4816DA6AAFC0A7A311CBE29423,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025302Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:28.673{4A7D70D7-4C46-6140-CC00-00000000F101}2772C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-574.attackrange.local50894-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000047135Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:30.503{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-61027- 354300x800000000000000047134Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:30.477{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local62040- 354300x800000000000000047133Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:30.477{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local61027- 10341000x800000000000000047132Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.411{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047131Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.411{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047130Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.411{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047129Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.411{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047128Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.411{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047127Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.410{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047126Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.410{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047125Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.352{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047124Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:32.352{C8F4C507-6258-6140-DE08-00000000F001}7016\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047123Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:32.332{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17899705080833647407C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047122Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:32.332{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17899705080833647407C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047121Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.324{C8F4C507-5C83-6140-A007-00000000F001}4224696C:\Windows\system32\csrss.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047120Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.324{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6258-6140-DE08-00000000F001}7016C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047119Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:32.308{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.3505009285782878886C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047118Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:32.308{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.3505009285782878886C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000025304Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:33.861{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3294E0DF896C7860994EF633A0890267,SHA256=EC8FFBBF553D1B8F836641DCDBB4BCB86DD8F6B165A14E73B7467D2FDAD60466,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047196Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.981{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047195Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.981{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047194Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.981{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047193Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.981{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047192Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.981{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047191Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.981{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047190Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.980{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047189Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.969{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047188Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.969{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047187Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.969{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047186Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.968{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047185Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.968{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047184Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.968{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047183Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.968{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047182Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.942{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047181Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.941{C8F4C507-6259-6140-E108-00000000F001}2316\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047180Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.928{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.16506612531010341666C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047179Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.928{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.16506612531010341666C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047178Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.923{C8F4C507-5C83-6140-A007-00000000F001}42245620C:\Windows\system32\csrss.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047177Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.923{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E108-00000000F001}2316C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047176Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.921{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.7609370729040577770C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047175Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.921{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.7609370729040577770C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047174Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.909{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.10341004427615672681C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047173Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.909{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.10341004427615672681C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047172Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.909{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047171Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.909{C8F4C507-6259-6140-E008-00000000F001}5440\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047170Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.899{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.1142401485339171778C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047169Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.899{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.1142401485339171778C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047168Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.895{C8F4C507-5C83-6140-A007-00000000F001}42241076C:\Windows\system32\csrss.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047167Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.895{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-E008-00000000F001}5440C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047166Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.893{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.5511056859536216324C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047165Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.892{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.5511056859536216324C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047164Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.836{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=47DB088923AB11C86AC954465C78CC5A,SHA256=E718B1299DD5366BA8AC7A62B0AE864A5353B95474D70C193A43AEA78365513B,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000047163Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.790{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17510250618657614259C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047162Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.790{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17510250618657614259C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047161Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.782{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.18265978341935526094C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047160Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.781{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.18265978341935526094C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047159Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.593{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047158Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.593{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047157Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.592{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047156Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.592{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047155Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.592{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047154Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.592{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047153Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.592{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047152Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.552{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047151Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.552{C8F4C507-6259-6140-DF08-00000000F001}1960\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047150Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.541{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.10099910091013745856C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047149Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.541{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.10099910091013745856C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047148Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.538{C8F4C507-5C83-6140-A007-00000000F001}42245620C:\Windows\system32\csrss.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047147Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.537{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6259-6140-DF08-00000000F001}1960C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047146Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.533{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.15738627630228837226C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047145Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.533{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.15738627630228837226C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047144Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.514{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.13015006674895985923C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047143Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.514{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.13015006674895985923C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047142Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:33.497{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.3210030104311509381C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047141Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:33.497{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.3210030104311509381C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047140Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.496{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local52378- 354300x800000000000000047139Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:31.496{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50168- 23542300x800000000000000025305Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:34.876{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEE9DF86300B930DF6132F7CC1B61FCE,SHA256=265AF717691B4530269310412B6A5651DBF6DBA8D0B16616B794B324781A0AA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047223Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.899{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B3528F7619813E87A1D814594874D0D4,SHA256=F3C382E3FF61E1569A9CA17D27C9BD8D3C41B94EDA0511BEDA4BEDE5D3D6330D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047222Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.574{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8749F2419164E6BC39CE42681E423019,SHA256=1DD6FADDA3C35A62EF8E9C2CE58073750519D46426121C134449C0AD8922BCD0,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047221Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:32.917{C8F4C507-61CB-6140-9408-00000000F001}4428www.bancobrasil.com.br0type: 5 www.dc.bb.com.br;170.66.192.50;170.66.11.10;C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047220Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.170{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local65281-false170.66.192.50-443https 354300x800000000000000047219Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.134{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local54308-false170.66.192.50-443https 354300x800000000000000047218Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:33.131{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50129-false170.66.192.50-443https 18141800x800000000000000047217Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.390{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.4526562818635909631C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047216Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:34.390{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.4526562818635909631C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047215Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.309{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625A-6140-E308-00000000F001}1752C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047214Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.309{C8F4C507-625A-6140-E308-00000000F001}1752\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047213Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.292{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17900939010625611239C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047212Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:34.292{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17900939010625611239C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047211Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.279{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625A-6140-E208-00000000F001}1816C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047210Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.278{C8F4C507-625A-6140-E208-00000000F001}1816\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047209Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.275{C8F4C507-5C83-6140-A007-00000000F001}4224696C:\Windows\system32\csrss.exe{C8F4C507-625A-6140-E308-00000000F001}1752C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047208Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.275{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625A-6140-E308-00000000F001}1752C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047207Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.273{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.2445849141878455009C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047206Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:34.273{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.2445849141878455009C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047205Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.257{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17736773618413555322C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047204Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:34.257{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17736773618413555322C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047203Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.241{C8F4C507-5C83-6140-A007-00000000F001}4224696C:\Windows\system32\csrss.exe{C8F4C507-625A-6140-E208-00000000F001}1816C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047202Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.241{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625A-6140-E208-00000000F001}1816C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047201Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.239{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.8901489725689205653C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047200Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:34.239{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.8901489725689205653C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047199Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.099{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BFBE10A8B6C0A069B59290CFAEE5C8A8,SHA256=1E541D9AA68326EF8C33477BA8E26E305B8FDC0441359BF885D1A63BB52CE55E,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000047198Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:34.012{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6150209004901433229C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047197Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:34.012{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6150209004901433229C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047230Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:35.904{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B09FB0FBB9905188A729F18511D90443,SHA256=7CE71079BE6881BBAEE58B63F3E09AA71E026D0CFA033CE250E01151FDED4C18,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025306Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:35.908{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B65BA08DCFDD5264D11DD0B4B45FE05E,SHA256=0A8401A21886C39BB6E0028B2AF27B76F516D61B98C4B531BE25CA0EBC5061D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047229Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:35.755{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=DE96205F5AFD20DDB7E6536D87CD39BD,SHA256=E2E75142DC8D0C5482CD2CD3C49AF5D36A0CBD0E3A4098CE96892CD8D91B2F55,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047228Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:35.755{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=29E6D19C8CAC038F0EC0AFF7DA1B997A,SHA256=49D9180CCAAE7CAA5957AAD1E44419CCB09327EE2A950D3C45BC96F1C1022E7F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047227Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.511{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local57493-false142.250.185.234fra16s53-in-f10.1e100.net443https 354300x800000000000000047226Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.146{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-64082- 354300x800000000000000047225Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.120{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local64082- 22542200x800000000000000047224Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.359{C8F4C507-61CB-6140-9408-00000000F001}4428www100.bb.com.br0170.66.72.5;C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000025307Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:36.939{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F4F276FA2E01E7D82346D0281D15874,SHA256=E778201111AF7D4665DE72A626C8B29636221A7EEB82BFA865CE8CF693B444D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047237Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:36.969{C8F4C507-4948-6140-2D00-00000000F001}2960NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=97307B6C6226AFFEFEDDF9EBA24D5EA3,SHA256=4CB856A974CB30F2D8F223261AE885385947BBAEFF3925236FB5B2D7588E78E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047236Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:36.911{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5EAE48B99D1874295B1157D74CDC5202,SHA256=28DF67B782FA4810EAF045D1001582E5152E101040B0D5C74CB24B52BC7A0686,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047235Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:35.333{C8F4C507-4953-6140-6D00-00000000F001}3440C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local57494-false10.0.1.12-8000- 354300x800000000000000047234Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.596{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local54998-false170.66.72.5-443https 354300x800000000000000047233Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.586{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local65328-false142.250.181.238fra16s56-in-f14.1e100.net443https 354300x800000000000000047232Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:34.584{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local60996-false170.66.72.5-443https 23542300x800000000000000047231Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:36.269{C8F4C507-61C9-6140-9108-00000000F001}2256ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Local State~RF624895.TMPMD5=0A15B1645BE60AF1BE6873A52916A9F3,SHA256=7D701D711429B77901BDCC59771B214ED4BEEC363F464F3687B09831589B8C82,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047279Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.930{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBFF27CDAA325142D279D182DE76CA29,SHA256=6FD7B047C457F51CA6BAA676A13D96A9C755E720BF4E1BE49AEFCF088419AB6D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025308Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:33.747{4A7D70D7-4C46-6140-CC00-00000000F101}2772C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-574.attackrange.local50895-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 18141800x800000000000000047278Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.922{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.2633474290371452720C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047277Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.922{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.2633474290371452720C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047276Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:36.590{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-49519- 354300x800000000000000047275Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:36.564{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local49519- 23542300x800000000000000047274Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.441{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C7611C123260FE0CEA95B3BE35A1CB3A,SHA256=C626E8107308CF803DE03C51A02C782565AB4E316C729FC89A10FA591E25FCD1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047273Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.372{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047272Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.372{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047271Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.372{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047270Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.372{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047269Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.372{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047268Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.370{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047267Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.370{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000047266Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.318{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.15734719303058130939C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047265Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.318{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.15734719303058130939C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047264Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.301{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047263Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.301{C8F4C507-625D-6140-E508-00000000F001}6308\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047262Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.287{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.4015426192600436257C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047261Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.287{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.4015426192600436257C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047260Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.279{C8F4C507-5C83-6140-A007-00000000F001}42241076C:\Windows\system32\csrss.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047259Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.277{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E508-00000000F001}6308C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047258Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.275{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.13922105229040200158C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047257Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.275{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.13922105229040200158C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047256Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.241{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047255Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.239{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047254Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.239{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047253Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.239{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047252Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.239{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047251Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.239{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047250Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.239{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000047249Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.215{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.8883226890286429334C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047248Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.214{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.8883226890286429334C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047247Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.207{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.9856119615100147951C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047246Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.207{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.9856119615100147951C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047245Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.183{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047244Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.183{C8F4C507-625D-6140-E408-00000000F001}4456\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047243Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.163{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.16868421880346209227C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047242Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.163{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.16868421880346209227C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047241Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.153{C8F4C507-5C83-6140-A007-00000000F001}42245620C:\Windows\system32\csrss.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047240Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.153{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-625D-6140-E408-00000000F001}4456C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047239Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:37.149{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.11267115645986164045C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047238Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:37.148{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.11267115645986164045C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047303Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.974{C8F4C507-61C9-6140-9108-00000000F001}2256ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF625324.TMPMD5=DCC6F6EC8CB57825DE39A09AC957E784,SHA256=E19CA66A25732528E6B60BFA71BDCA135A1E0AD052F5B30DC9FF5AD9537457B3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047302Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.941{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7B0890E8761143DE92FF49DCD335138A,SHA256=3F6E05A50C6025A6244D2E248B318BF49E250491ADEE6E9B573C099C142A394A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025309Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:38.033{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8BAE68AAF311764BE71DDB44990B632F,SHA256=880B0D053BF3E9EE176C251C7AAF9D37B24E25C152D24144A0D0E338CE0305AC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047301Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.735{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local62005-false170.66.11.10www.bb.com.br443https 354300x800000000000000047300Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.652{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local59695-false142.250.185.163fra16s51-in-f3.1e100.net443https 354300x800000000000000047299Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.513{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local64228-false185.199.110.133cdn-185-199-110-133.github.com443https 354300x800000000000000047298Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.513{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56853-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047297Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.513{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56591-false185.199.110.133cdn-185-199-110-133.github.com443https 354300x800000000000000047296Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.513{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local59767-false185.199.110.133cdn-185-199-110-133.github.com443https 354300x800000000000000047295Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.475{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local60235-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047294Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.475{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50904-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047293Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.474{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local58577-false185.199.110.133cdn-185-199-110-133.github.com443https 354300x800000000000000047292Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.471{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local57598-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047291Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.467{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local57725-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047290Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.467{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local63752-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047289Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.467{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local58942-false185.199.109.154cdn-185-199-109-154.github.com443https 354300x800000000000000047288Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.462{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local63402- 354300x800000000000000047287Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.462{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local65166- 354300x800000000000000047286Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.409{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local51719-false140.82.121.3lb-140-82-121-3-fra.github.com443https 354300x800000000000000047285Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.404{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local52741- 354300x800000000000000047284Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.271{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50450- 354300x800000000000000047283Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.072{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local57495-false10.0.1.12-8089- 22542200x800000000000000047282Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.474{C8F4C507-61CB-6140-9408-00000000F001}4428avatars.githubusercontent.com0185.199.110.133;185.199.111.133;185.199.108.133;185.199.109.133;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047281Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.416{C8F4C507-61CB-6140-9408-00000000F001}4428github.com0140.82.121.3;C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047280Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.162{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F1362D5F8E8C1F6432EE17E05676C61A,SHA256=CF1A932F08C617F0F3F3CB4D7CC5CFBD92AB28F452B1222F0BA5A9E95C9FBE16,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047308Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:39.949{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C3CC9653EC04CBA11FF51D87B345C52,SHA256=BCF12922F556160A5BE1728AD8E8079FD91FF9C28A6EC6565BCBB377796A0C19,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025310Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:39.064{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1246BA768854BB20493D9FAE824E3D88,SHA256=EE725E43B172972B6A1F6F5E333FF8B31A46E3AA425871FF20232F9EF6F8900A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047307Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.479{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local49651-false142.250.185.98fra16s49-in-f2.1e100.net443https 354300x800000000000000047306Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.370{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local59110-false142.250.185.234fra16s53-in-f10.1e100.net443https 22542200x800000000000000047305Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:37.474{C8F4C507-61CB-6140-9408-00000000F001}4428github.githubassets.com0185.199.109.154;185.199.110.154;185.199.111.154;185.199.108.154;C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047304Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:39.471{C8F4C507-61CB-6140-9408-00000000F001}4428ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF625518.TMPMD5=F30B0F7F013DC2EE664669AB8E410B81,SHA256=BFB1FD98F921F57097B586B4278AB74A204E7B5551B2B2A3150484487ADD17CC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047315Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:40.950{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD155D813EF6B0C51F6C91B9E0E88F8B,SHA256=F4EAD64F7E71540ED506F6A996DDEF9530446683ABB151AE157194174C69EDDF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025311Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:40.079{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2C90BA9919050AD585D934826E2FD84,SHA256=CBD5E88C2FE0A4210A3057580476909C41AEC6E957532212A5CD33CE261D7BC1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047314Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:39.514{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local55918-false170.66.72.2-443https 354300x800000000000000047313Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:39.477{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50007-false170.66.72.2-443https 354300x800000000000000047312Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.576{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50361- 354300x800000000000000047311Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.576{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59050- 354300x800000000000000047310Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:38.576{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50257- 22542200x800000000000000047309Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:39.268{C8F4C507-61CB-6140-9408-00000000F001}4428eni.bb.com.br0170.66.72.2;C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047317Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:41.982{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B9F6160F1DBB216722D703CF615951B7,SHA256=7B0D8A1E9B062748FDC7B7D7C76F104790F4FE7BD4919C6B9530C91E2E4702AC,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047316Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:39.553{C8F4C507-61CB-6140-9408-00000000F001}4428github9003-C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000025312Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:41.095{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DCDAF29775965C9938BBC588DFF52D97,SHA256=F470CB68F956A338FA5DF49F37AC14F760A5DBFA357089343FC9B048A6E1A4ED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025313Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:42.111{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED579FEBB90D7EE28C19671B49F46CBB,SHA256=9789798DDAEB8C522D5B372B157A23EE2E8439908DF30FF431A024AE2172102B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047319Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:40.621{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-59862- 354300x800000000000000047318Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:40.595{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59862- 354300x800000000000000025315Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:39.763{4A7D70D7-4C46-6140-CC00-00000000F101}2772C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-574.attackrange.local50896-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025314Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:43.126{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4922C804533ABCECA776144B92590D80,SHA256=87CB53EF218ECCE46171B02249B408D038D1E21F89B76FDFD3D0C5B38C02A4D5,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047333Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.973{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6263-6140-E608-00000000F001}5672C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047332Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:43.973{C8F4C507-6263-6140-E608-00000000F001}5672\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047331Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:43.973{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.9870278376198288533C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047330Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:43.973{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.9870278376198288533C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047329Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.942{C8F4C507-5C83-6140-A007-00000000F001}4224696C:\Windows\system32\csrss.exe{C8F4C507-6263-6140-E608-00000000F001}5672C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047328Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.942{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6263-6140-E608-00000000F001}5672C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047327Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:43.942{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17215606942422071260C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047326Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:43.942{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.17215606942422071260C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047325Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.566{C8F4C507-4936-6140-0B00-00000000F001}6322276C:\Windows\system32\lsass.exe{C8F4C507-4934-6140-0100-00000000F001}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96ef2|C:\Windows\system32\kerberos.DLL+793e4|C:\Windows\system32\kerberos.DLL+1443f|C:\Windows\system32\lsasrv.dll+2d211|C:\Windows\system32\lsasrv.dll+2b3d4|C:\Windows\system32\lsasrv.dll+30929|C:\Windows\system32\lsasrv.dll+2e287|C:\Windows\system32\lsasrv.dll+2d211|C:\Windows\system32\lsasrv.dll+15ded|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 354300x800000000000000047324Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:42.522{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56816-false170.66.11.10www.bb.com.br443https 354300x800000000000000047323Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:42.297{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local59513-false170.66.11.10www.bb.com.br443https 354300x800000000000000047322Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:42.172{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local52968-false170.66.11.10www.bb.com.br443https 354300x800000000000000047321Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:41.146{C8F4C507-4953-6140-6D00-00000000F001}3440C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local55919-false10.0.1.12-8000- 23542300x800000000000000047320Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.012{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DFBA8871DB0AAB55C90BCFD9D7C38ED,SHA256=A07909645D9109881C1BEE17B3555F497BA1D82F88037AACF5BBB0599E293419,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025316Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:44.142{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06993AE34B267DA9AFF20508C8BCC832,SHA256=0EA5D63603A631E716FDFC99D270BA4176076FA3DF8013798C14B3E6617F570D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047341Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.582{C8F4C507-4936-6140-0B00-00000000F001}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-158.attackrange.local56818-false10.0.1.14win-dc-158.attackrange.local389ldap 354300x800000000000000047340Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.582{C8F4C507-4938-6140-1600-00000000F001}1324C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local56818-false10.0.1.14win-dc-158.attackrange.local389ldap 354300x800000000000000047339Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.571{C8F4C507-4936-6140-0B00-00000000F001}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local56817-truefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local389ldap 354300x800000000000000047338Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.571{C8F4C507-4938-6140-1600-00000000F001}1324C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local56817-truefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local389ldap 23542300x800000000000000047337Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:44.456{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D6E89303A032F1743EC145B959092D7B,SHA256=D2FC6F1FD6218EECF53FD7CCF79649E34B5C79CCBC596CBA1C8CF05E17CCFEDB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047336Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:44.456{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C14F7983AF6CC403DD8E1EFC8606144D,SHA256=6057930F1EF4EADED092B56D28E3BC8E5749E0C5ED588FB51B71903D2F6BAC42,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047335Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:44.303{C8F4C507-61C9-6140-9108-00000000F001}2256ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\ADMINI~1\AppData\Local\Temp\2\chrome_BITS_2256_1751195639\0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crxMD5=B92BBCFD3C31F799C5863D78154DB555,SHA256=6F6BC93DCD62DC251850D2FF458FDA96083CEB7FBE8EEB11248B8485EF2AEA23,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047334Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:44.030{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=585A6B775D2BF7FCB5ED15B8350FED33,SHA256=355442CF22E4C911B2CE2F1C2C0FAA0F7B3E1BEFAD829E8AC887CAD3935B55CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025317Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:45.149{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=882C601A9647CEDFE75FA75D81BC8FBF,SHA256=105CCC1EB8F310A69DA8DE7D9707F2669EB71CC212047825CDDC7925BA6F562C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047353Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:44.430{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local51611-false142.250.181.227fra16s56-in-f3.1e100.net443https 354300x800000000000000047352Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.692{C8F4C507-4934-6140-0100-00000000F001}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local56819-truefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local445microsoft-ds 354300x800000000000000047351Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:43.692{C8F4C507-4934-6140-0100-00000000F001}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local56819-truefe80:0:0:0:d95c:c36c:7423:d3edwin-dc-158.attackrange.local445microsoft-ds 23542300x800000000000000047350Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.572{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\datareporting\glean\db\data.safe.binMD5=E2943BEF20C5436E5B36EB89FC997D42,SHA256=8F8491DB7BBF660D59D1021C51E099035FB80EA9D4B58BE968DBD99FECFF46DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047349Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.571{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\datareporting\glean\db\data.safe.binMD5=FD030627EC9E381B6A3F10D8700C007C,SHA256=E94A769D39EEC5BBB86667A4582E5015BCCD1F13FADF16272B922C07047487F8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047348Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.569{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\datareporting\glean\db\data.safe.binMD5=EB1B03D5937DCB50A7897BC6C0708B12,SHA256=BDC38BA53D2C825E1680F9F30AEFA8037FE57946DE9FF3D50247CE1D1C3C53C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047347Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.568{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\datareporting\glean\db\data.safe.binMD5=93568DA6306B04E87A98AE6EB72FD008,SHA256=0AAD74572B68964B4AABDE13649E5CCE41CA92BF621E53DE5D2841CC2A0FA918,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047346Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.567{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\datareporting\glean\db\data.safe.binMD5=B3E8516770DBE991DE5359503A9D4893,SHA256=0428ABDD704E60AD0905F7A82D3C4A816607B5043BFB47ADE896059D5943AD83,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047345Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.566{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\datareporting\glean\db\data.safe.binMD5=AE2E7FA79A760265281790BB6EEA9EBE,SHA256=4B8054F542CC1D9A93C871A444B0D21DFA1EF8FC67641137204AEE8A15DDFCB5,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000047344Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:45.335{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.1832683540006258865C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047343Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:45.335{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.1832683540006258865C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047342Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.041{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E08FA13FEC809B760842A114C46F91C,SHA256=284684540E52C9733A5B2CB901A3C7EBDD27061F076F96CB6C6594F74477E0E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025318Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:46.165{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE5EA7DFC57E16A535302A3F200AAB05,SHA256=438A651F7C3D096EF7C1E15DC7B349BB66909D02A7A2AA37B15421878743D713,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047355Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:44.893{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56228-false170.66.11.10www.bb.com.br443https 23542300x800000000000000047354Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:46.056{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6996A2B00451F909EDA2CF4E802D4314,SHA256=D5E14BC116B2F84DA0EC8233769987B8E54A6467DA864D807E8D39426C8EA21C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047368Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.837{C8F4C507-6267-6140-E708-00000000F001}62925284C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000047367Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:46.255{C8F4C507-4953-6140-6D00-00000000F001}3440C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local56229-false10.0.1.12-8000- 354300x800000000000000047366Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:45.677{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local63306-false142.250.181.234fra16s56-in-f10.1e100.net443https 10341000x800000000000000047365Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-6267-6140-E708-00000000F001}6292C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047364Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047363Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047362Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4936-6140-0500-00000000F001}416532C:\Windows\system32\csrss.exe{C8F4C507-6267-6140-E708-00000000F001}6292C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047361Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047360Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047359Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.590{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-6267-6140-E708-00000000F001}6292C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047358Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.591{C8F4C507-6267-6140-E708-00000000F001}6292C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000047357Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.175{C8F4C507-61C9-6140-9108-00000000F001}2256ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Local State~RF627320.TMPMD5=0B42401854BF2F95A9A56B4263356FCD,SHA256=49BBE7F3DE2DF8D1A6D0B72203D421F25075B2D781F8916F0AC8C731FADEC481,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047356Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:47.059{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DFFEE2E45A7CDF09410C59A2366A2B8A,SHA256=9429FAC9D4C1421B9A8C1051B1E75DC10C55138B241738426C14D2AF2547DEE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025319Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:47.165{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B71F8E3069D26275DE519FC436B087B7,SHA256=0CECB04B820E35D4D8C37554292665723050850022CF88FAF0607F535562362D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025321Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:44.789{4A7D70D7-4C46-6140-CC00-00000000F101}2772C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-574.attackrange.local50897-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025320Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:48.180{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=463EC835A56D9B63B29B58906C9811F4,SHA256=F7AD9601BB26D8362DFA597F045696AFC97ADFBF2E1DAA1F415F29ED43E7A548,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047386Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-6268-6140-E908-00000000F001}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047385Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047384Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047383Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047382Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047381Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4936-6140-0500-00000000F001}41696C:\Windows\system32\csrss.exe{C8F4C507-6268-6140-E908-00000000F001}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047380Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.921{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-6268-6140-E908-00000000F001}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047379Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.922{C8F4C507-6268-6140-E908-00000000F001}2052C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000047378Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.605{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D6E89303A032F1743EC145B959092D7B,SHA256=D2FC6F1FD6218EECF53FD7CCF79649E34B5C79CCBC596CBA1C8CF05E17CCFEDB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047377Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-6268-6140-E808-00000000F001}2344C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047376Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4936-6140-0500-00000000F001}41696C:\Windows\system32\csrss.exe{C8F4C507-6268-6140-E808-00000000F001}2344C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047375Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047374Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047373Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047372Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047371Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.258{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-6268-6140-E808-00000000F001}2344C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047370Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.259{C8F4C507-6268-6140-E808-00000000F001}2344C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000047369Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:48.074{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F32C9E87FB7951708069DEE402BDE776,SHA256=8B11BBD106EE17A5D5D43C1AF201E6E0144D136CECEA158E9719ADE91289F365,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047389Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.939{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0EADD0B44CB028D2C3315B3B8EA9B42E,SHA256=B3E9045F916C721904B499857D95C204ECC4174851E71091C082559756FC3E04,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047388Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.858{C8F4C507-61CB-6140-9408-00000000F001}4428ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF627daf.TMPMD5=593F3099E9F0DC49D959EC492BC4411C,SHA256=21D516C41588EB2FE214DD0FCF972B0ED8F6669E5061B710DEABDA7C691C5E1D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047387Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.090{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=58F14AEBFD3FC04B18A8B499F51F6E34,SHA256=D834EC1B591CA2D1D49EEFF0843DF3004681CC90FFB67A2BCEBA964D8EB2B693,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025322Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:49.196{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1686FA6CDE910A10FA57C8732C34E7D2,SHA256=2BC260B9DB73302BA603C153BD854D5E8AE47B634D6E04DD6C5268216DB9631B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025323Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:50.212{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F4EFE9FE557BD9B3008F0FDDE1115931,SHA256=B7979CD8FBAA874ED301CF2F4772BDE61B95E43C30757B9B2B10F78A4A2AF54C,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047436Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.422{C8F4C507-61CB-6140-9408-00000000F001}4428s.yimg.com0type: 5 edge.gycpi.b.yahoodns.net;87.248.118.23;87.248.118.22;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047435Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.405{C8F4C507-61CB-6140-9408-00000000F001}4428connect.facebook.net0type: 5 scontent.xx.fbcdn.net;157.240.20.19;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047434Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.370{C8F4C507-61CB-6140-9408-00000000F001}4428snap.licdn.com0type: 5 wildcard.licdn.com.edgekey.net;type: 5 e9706.dscg.akamaiedge.net;23.210.253.242;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047433Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.282{C8F4C507-61CB-6140-9408-00000000F001}4428www.google.de0142.250.185.131;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047432Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.275{C8F4C507-61CB-6140-9408-00000000F001}4428analytics.google.com0type: 5 www3.l.google.com;142.250.185.206;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047431Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.199{C8F4C507-61CB-6140-9408-00000000F001}4428apimesabi.relacionamento360.com.br020.55.56.125;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047430Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.268{C8F4C507-61CB-6140-9408-00000000F001}4428www101.bb.com.br0170.66.72.4;C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047429Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.493{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local58727-false170.66.72.4-443https 354300x800000000000000047428Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.077{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-50369- 354300x800000000000000047427Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:49.044{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50369- 23542300x800000000000000047426Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.639{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC5C190C74161C721B38866D8A22F1D6,SHA256=3E908315FC3D34D2DEDAA3545E043414E42E5C917399867536216912495DA1C4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047425Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047424Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047423Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047422Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047421Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047420Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047419Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.544{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000047418Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.511{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.550887860240040029C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047417Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:50.511{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.550887860240040029C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047416Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.482{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047415Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.482{C8F4C507-626A-6140-EB08-00000000F001}6828\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047414Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.469{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.13972529633406323820C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047413Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:50.469{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.13972529633406323820C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047412Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.461{C8F4C507-5C83-6140-A007-00000000F001}42241076C:\Windows\system32\csrss.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047411Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.460{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EB08-00000000F001}6828C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047410Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.458{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.17879061143617033499C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047409Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:50.458{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.17879061143617033499C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047408Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.429{C8F4C507-61C9-6140-9108-00000000F001}2256ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF627fe1.TMPMD5=163C43F78CB31EE275414DA80796BEAF,SHA256=7E7981BBC961E49A0101558A067DB8752CEB0A057A4C77742596C387DE5DBA9A,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000047407Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.399{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.2180815116807454247C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047406Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:50.399{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.2180815116807454247C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047405Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.373{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047404Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.373{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047403Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.368{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047402Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.365{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047401Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.365{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047400Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.365{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047399Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.365{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047398Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.298{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047397Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.298{C8F4C507-626A-6140-EA08-00000000F001}4948\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047396Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.277{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.15076547628792722483C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047395Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:50.277{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.15076547628792722483C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047394Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.268{C8F4C507-5C83-6140-A007-00000000F001}42241076C:\Windows\system32\csrss.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047393Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.268{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626A-6140-EA08-00000000F001}4948C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047392Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:50.266{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.9079351659669059288C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047391Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:50.266{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.9079351659669059288C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047390Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.117{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CF7F219F8F855624C05AF9DBDB128108,SHA256=B5AED2D479FE998E726A18D06EEA8101BAED86B42A6D1CC67207C334B70187F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025324Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:51.227{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E9E9E85002E516FA37FAE06393F59D9B,SHA256=2915E96542A0CA79BA047E455BB0ED953CE90291C2D1B654AE4C6B77F17157F3,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047490Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.557{C8F4C507-61CB-6140-9408-00000000F001}4428www.facebook.com0type: 5 star-mini.c10r.facebook.com;157.240.20.35;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047489Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.040{C8F4C507-61CB-6140-9408-00000000F001}4428www.linkedin.com0type: 5 www-linkedin-com.l-0005.l-msedge.net;type: 5 l-0005.l-msedge.net;13.107.42.14;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047488Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.590{C8F4C507-61CB-6140-9408-00000000F001}4428adservice.google.de0type: 5 pagead46.l.doubleclick.net;142.250.185.162;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047487Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.567{C8F4C507-61C9-6140-9108-00000000F001}2256apps.identrust.com0type: 5 apps.digsigtrust.com;::ffff:192.35.177.64;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047486Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.538{C8F4C507-61CB-6140-9408-00000000F001}4428px.ads.linkedin.com0type: 5 mix.linkedin.com;type: 5 glb-na.mix.linkedin.com;type: 5 pop-esv5.mix.linkedin.com;108.174.11.37;C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047485Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.768{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=241300145DF836E8FFB20B7A90A5E89C,SHA256=2AA0AD9C3E6583AC1A069366B1F6BD4789A7B06B3F8F7628D10159A19817EC2D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047484Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.767{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=DE96205F5AFD20DDB7E6536D87CD39BD,SHA256=E2E75142DC8D0C5482CD2CD3C49AF5D36A0CBD0E3A4098CE96892CD8D91B2F55,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047483Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.742{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local52690- 354300x800000000000000047482Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.711{C8F4C507-61C9-6140-9108-00000000F001}2256C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61903-false192.35.177.64-80http 354300x800000000000000047481Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.680{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61902-false108.174.11.37108-174-11-37.fwd.linkedin.com443https 354300x800000000000000047480Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.656{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local54126-false20.55.56.125-443https 354300x800000000000000047479Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.645{C8F4C507-4936-6140-0B00-00000000F001}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59412-true0:0:0:0:0:0:0:1win-dc-158.attackrange.local389ldap 354300x800000000000000047478Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.645{C8F4C507-4948-6140-2700-00000000F001}2876C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59412-true0:0:0:0:0:0:0:1win-dc-158.attackrange.local389ldap 354300x800000000000000047477Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.583{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local59411-false142.250.185.162fra16s51-in-f2.1e100.net443https 354300x800000000000000047476Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.581{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local65447- 354300x800000000000000047475Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.528{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58077- 354300x800000000000000047474Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.520{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61207-false87.248.118.23e2.ycpi.vip.deb.yahoo.com443https 354300x800000000000000047473Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.513{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local63786-false142.250.185.131fra16s50-in-f3.1e100.net443https 354300x800000000000000047472Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.481{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local58076-false142.250.184.230fra24s12-in-f6.1e100.net443https 354300x800000000000000047471Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.432{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local55141-false87.248.118.23e2.ycpi.vip.deb.yahoo.com443https 354300x800000000000000047470Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.412{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local64164- 354300x800000000000000047469Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.411{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-58075- 354300x800000000000000047468Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.401{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50609-false142.250.184.230fra24s12-in-f6.1e100.net443https 354300x800000000000000047467Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.399{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local59353-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047466Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.395{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local49601- 354300x800000000000000047465Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.387{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59639- 354300x800000000000000047464Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.383{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58075- 354300x800000000000000047463Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.363{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local60664-false23.210.253.242a23-210-253-242.deploy.static.akamaitechnologies.com443https 354300x800000000000000047462Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.360{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local61160- 354300x800000000000000047461Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.330{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local64593-false173.194.76.157ws-in-f157.1e100.net443https 354300x800000000000000047460Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.304{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local58074-false142.250.185.110fra16s49-in-f14.1e100.net443https 354300x800000000000000047459Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.279{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local62840-false20.55.56.125-443https 354300x800000000000000047458Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.277{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local64492-false173.194.76.157ws-in-f157.1e100.net443https 354300x800000000000000047457Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.277{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local63325-false142.250.185.131fra16s50-in-f3.1e100.net443https 10341000x800000000000000047456Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.522{C8F4C507-626B-6140-EC08-00000000F001}52083916C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047455Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.338{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-626B-6140-EC08-00000000F001}5208C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047454Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.336{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047453Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.336{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047452Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.336{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047451Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.335{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047450Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.335{C8F4C507-4936-6140-0500-00000000F001}41696C:\Windows\system32\csrss.exe{C8F4C507-626B-6140-EC08-00000000F001}5208C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047449Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.335{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-626B-6140-EC08-00000000F001}5208C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047448Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.334{C8F4C507-626B-6140-EC08-00000000F001}5208C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000047447Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.274{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8FAD1D34BAAFED5E2EBDF420C0E88052,SHA256=70AF7E0917A2088CBC8B85CC7863729BC30EE2B6F6586C3472055A618066A229,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047446Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.270{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58542- 354300x800000000000000047445Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.268{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local52043-false142.250.185.206fra16s52-in-f14.1e100.net443https 354300x800000000000000047444Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.265{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58729- 354300x800000000000000047443Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.183{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58410- 354300x800000000000000047442Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.151{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56692-false142.250.185.110fra16s49-in-f14.1e100.net443https 354300x800000000000000047441Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.147{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local49240- 354300x800000000000000047440Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.144{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local58069-false142.250.186.104fra24s06-in-f8.1e100.net443https 23542300x800000000000000047439Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.125{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C65427F176EED73077DD4501989A4E8,SHA256=817E0847EB968CDD2A367C2BCC9B2032AF1E0B2F95443B3B3E6D34C06FBD41A6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047438Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.043{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56373-false142.250.186.104fra24s06-in-f8.1e100.net443https 354300x800000000000000047437Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:50.040{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51453- 23542300x800000000000000025325Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:52.243{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B3E9501B1D678BA428CC2890023F044,SHA256=F3EEEABC65A6946B82C5AEF0B6C349FF9EDD1BBC786990051430CC9DCE9958D2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047511Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.888{C8F4C507-626C-6140-ED08-00000000F001}28444508C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000047510Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.748{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51364- 354300x800000000000000047509Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.748{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local62321- 354300x800000000000000047508Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.748{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51883- 354300x800000000000000047507Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.747{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59894- 354300x800000000000000047506Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.747{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59707- 354300x800000000000000047505Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.550{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61223-false157.240.20.35edge-star-mini-shv-02-frt3.facebook.com443https 354300x800000000000000047504Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.448{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local64465-false212.82.100.181spdc.pbp.vip.ir2.yahoo.com443https 354300x800000000000000047503Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.188{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local60283-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047502Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.035{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local56131-false13.107.42.14-443https 354300x800000000000000047501Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.030{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59031- 10341000x800000000000000047500Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.585{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-626C-6140-ED08-00000000F001}2844C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047499Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.584{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047498Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.583{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047497Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.583{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047496Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.583{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047495Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.583{C8F4C507-4936-6140-0500-00000000F001}416532C:\Windows\system32\csrss.exe{C8F4C507-626C-6140-ED08-00000000F001}2844C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047494Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.583{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-626C-6140-ED08-00000000F001}2844C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047493Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.582{C8F4C507-626C-6140-ED08-00000000F001}2844C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000047492Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.340{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=34B627292273F511109CC34D37A59CBA,SHA256=CCC83ED78B5A471DE22384930DDB6D0F9F6F9137684E532AAFF470D177907B17,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047491Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.175{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FDB8BD05A72B82E9DEFF3385C347AB4B,SHA256=F7000EB281DD231D54F4A1FC08BC6B789BFA7D3341B72CCDD0C13CD9D3371631,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047546Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.133{C8F4C507-4953-6140-6D00-00000000F001}3440C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local61224-false10.0.1.12-8000- 354300x800000000000000047545Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.774{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-58219- 354300x800000000000000047544Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.773{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-51883- 354300x800000000000000047543Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.749{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58219- 354300x800000000000000047542Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:51.749{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58078- 10341000x800000000000000047541Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.617{C8F4C507-626D-6140-EF08-00000000F001}40566956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000047540Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.587{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7B5401015EB4F479A3C1C91A3015A0B5,SHA256=E2758864EC29FD215E6B9F8E3AB036597804E2C9A7077D9C194408C9114F0BD6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047539Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.468{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA9B97B025B272ED8B1556C4019248C7,SHA256=2CE838CFECA7CBDD968BD2195DF08DDEF609F50B7D2FDC5B2EE4C3862BD5A0A0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047538Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.373{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-626D-6140-EF08-00000000F001}4056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047537Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:53.372{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.10818494340413336717C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047536Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:53.372{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.10818494340413336717C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047535Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.370{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047534Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.370{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047533Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.370{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047532Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.370{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047531Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.370{C8F4C507-4936-6140-0500-00000000F001}41696C:\Windows\system32\csrss.exe{C8F4C507-626D-6140-EF08-00000000F001}4056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047530Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.369{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-626D-6140-EF08-00000000F001}4056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047529Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.369{C8F4C507-626D-6140-EF08-00000000F001}4056C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 18141800x800000000000000047528Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:53.354{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.9790672831964841642C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047527Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:53.354{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.9790672831964841642C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000025326Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:53.258{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE3E593B8C51BA71C83EA856080D3CDB,SHA256=EDA9F06F4EF8C6017B6F339EB5D4570A51607D4F3CCDA71A860E30A49DB4A7C9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047526Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047525Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047524Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047523Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047522Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047521Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047520Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.082{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047519Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.045{C8F4C507-61C9-6140-9208-00000000F001}3664648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047518Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:53.045{C8F4C507-626D-6140-EE08-00000000F001}524\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047517Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:53.033{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.13341630868378803081C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047516Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:53.033{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.13341630868378803081C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047515Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.025{C8F4C507-5C83-6140-A007-00000000F001}4224696C:\Windows\system32\csrss.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047514Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.024{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-626D-6140-EE08-00000000F001}524C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047513Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:53.021{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.15102286867507332913C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047512Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:53.021{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.15102286867507332913C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047566Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.504{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local60964-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047565Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.504{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local57957-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047564Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.504{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local49415-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047563Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.503{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50751-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047562Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.503{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local64737-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047561Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.502{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local63814-false157.240.20.19xx-fbcdn-shv-02-frt3.fbcdn.net443https 354300x800000000000000047560Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.497{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51617- 354300x800000000000000047559Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.267{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local60044-false157.240.20.35edge-star-mini-shv-02-frt3.facebook.com443https 354300x800000000000000047558Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.761{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59205- 354300x800000000000000047557Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.759{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local63472- 354300x800000000000000047556Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:52.753{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local52000- 23542300x800000000000000047555Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.636{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9B3EB884F16944059F95BB2395D4CE14,SHA256=CD5194882718816745969CFFF448C7F2165410818C26471D94603796996BDF82,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025328Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:54.274{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E26AB7291D9B54509A4B892883743518,SHA256=7280A933A23DEABE5CBBB4994A4F409873EF55F7D0C1C4ACD8A53C507431A2FC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047554Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.057{C8F4C507-4949-6140-3700-00000000F001}33563376C:\Windows\system32\conhost.exe{C8F4C507-626E-6140-F008-00000000F001}5444C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047553Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.053{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047552Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.053{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047551Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.053{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047550Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.053{C8F4C507-4937-6140-0C00-00000000F001}8482388C:\Windows\system32\svchost.exe{C8F4C507-4948-6140-2900-00000000F001}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047549Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.052{C8F4C507-4936-6140-0500-00000000F001}41696C:\Windows\system32\csrss.exe{C8F4C507-626E-6140-F008-00000000F001}5444C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047548Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.052{C8F4C507-4948-6140-2D00-00000000F001}29603456C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{C8F4C507-626E-6140-F008-00000000F001}5444C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 154100x800000000000000047547Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:54.050{C8F4C507-626E-6140-F008-00000000F001}5444C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{C8F4C507-4936-6140-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{C8F4C507-4948-6140-2D00-00000000F001}2960C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000025327Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:50.738{4A7D70D7-4C46-6140-CC00-00000000F101}2772C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-574.attackrange.local50898-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000047570Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:55.643{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF64B0470D441949E7EFF2B7B70B8D3A,SHA256=E2D9A5E9E962A418D10F7E12B887F71A82F6AF962D00F4FCA356D2914764DEBA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025329Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:55.290{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=407A691CC5008BC58B7E04BE0D6C42D5,SHA256=24D99E36A0B2233B39EC352CAF25D42E1DC69B518DD1210DF46D016B1DEC4792,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047569Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.507{C8F4C507-61CB-6140-9408-00000000F001}4428static.xx.fbcdn.net0type: 5 scontent.xx.fbcdn.net;157.240.20.19;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047568Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:53.166{C8F4C507-61CB-6140-9408-00000000F001}4428facebook.com0157.240.20.35;C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047567Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:55.058{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=60DBC13ADC409669E588A4D069B49B1E,SHA256=7328737BF65A02CA5F2F68A106408C701DA769D1C107CF4A0DF4862588AD43EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047571Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:56.658{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C2E2E2C8EB87FC319FE75C0A67EEDEB5,SHA256=A270BB7CBB648C640889CF0ABACE65A877C5DA9B7468727D2DB6C95725320B1D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025330Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:56.305{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F176539A44DB306E3D24016B5A7ECFC,SHA256=6D3B69CD66EAF8EE3D7E28DD960A25DB43FF166CF0CBCE94F639620BC5F156D4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047573Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:56.042{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratorudptruefalse10.0.1.14win-dc-158.attackrange.local62151-false142.250.185.206fra16s52-in-f14.1e100.net443https 23542300x800000000000000047572Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:57.661{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BBE3B23C70C107DF3B5E056E485A739C,SHA256=07EDEF8579420DCFFE189E7328B29D7C42C0DF7291AA7E6D507DE50814A48174,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025331Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:57.321{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=35F20186EF08D6FAB7140E209AFD9A96,SHA256=DB59B264E3E6A44A258F9A30F5F588B51817C90E1A3B35CDAD15DE260CECF265,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047590Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:57.340{C8F4C507-4953-6140-6D00-00000000F001}3440C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-158.attackrange.local60965-false10.0.1.12-8000- 23542300x800000000000000047589Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.673{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=04D264138F5B1A9B07DA02226DCA474A,SHA256=BBA45CCF7BABCED8DA9837650DC9A1F9AC1CBB804023952457F022984F98B25A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025332Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:58.337{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC1C2401BD555EEB92EEA8CF552DBC23,SHA256=7A64E3571A60CF9D8EC5994F5A8B3B0597C78ADD8A423C14D98B0441EF9C9CB3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047588Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047587Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047586Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047585Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047584Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047583Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047582Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.536{C8F4C507-61C9-6140-9108-00000000F001}22563920C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x101451C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e8a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+973e35|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f512|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+d3f28a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5e850e|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3687cc2|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a548|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+317a669|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3b9274a|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3a40bdc|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b0f6c|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+31131af|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+5a784|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+921773|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39926|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b396a4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+18c7ece|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+b39493|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000047581Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.500{C8F4C507-61C9-6140-9208-00000000F001}36645648C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x1f3fffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Google\Chrome\Application\chrome.exe+3e13f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047580Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:58.500{C8F4C507-6272-6140-F108-00000000F001}6168\crashpad_2256_QIVMBVIRDSVQPOOJC:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047579Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:58.480{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.11940303480563738776C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047578Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:58.480{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.11940303480563738776C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047577Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.473{C8F4C507-5C83-6140-A007-00000000F001}4224696C:\Windows\system32\csrss.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f 10341000x800000000000000047576Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.473{C8F4C507-61C9-6140-9108-00000000F001}22564156C:\Program Files\Google\Chrome\Application\chrome.exe{C8F4C507-6272-6140-F108-00000000F001}6168C:\Program Files\Google\Chrome\Application\chrome.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\ADVAPI32.dll+188af|C:\Program Files\Google\Chrome\Application\chrome.exe+3f075|C:\Program Files\Google\Chrome\Application\chrome.exe+ae1f5|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+29cf454|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd4551|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd39e4|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+cd3439|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+32b27cd|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30d607|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3788365|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+37872c1|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+3786ba8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+30dbd8|C:\Program Files\Google\Chrome\Application\93.0.4577.82\chrome.dll+8c8edc|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 18141800x800000000000000047575Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:58.467{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.8862963612726269550C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047574Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:58.467{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.5724.8862963612726269550C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047600Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.765{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50560-false98.137.11.163media-router-fp74.prod.media.vip.gq1.yahoo.com443https 354300x800000000000000047599Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.764{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50502-false98.137.11.163media-router-fp74.prod.media.vip.gq1.yahoo.com443https 354300x800000000000000047598Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.606{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50758- 23542300x800000000000000047597Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.681{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F0C75E8714B3F211D828A59BAEDDC3A8,SHA256=5789E2D9F6D97B8C293A1A3755901AA8C2F672C0BA536F3657E530D7187DE61D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025333Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:59.352{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=483C5D5070A02065893B0E9CAA07CD9B,SHA256=9A235105F9F8C814ED3D368059312B74992B888837E0F37B4106A5D8AE423CD8,IMPHASH=00000000000000000000000000000000falsetrue 18141800x800000000000000047596Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:59.571{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6777450270607759921C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047595Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:59.571{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.6777450270607759921C:\Program Files\Google\Chrome\Application\chrome.exe 18141800x800000000000000047594Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-ConnectPipe2021-09-14 08:50:59.553{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.15484067981633429150C:\Program Files\Google\Chrome\Application\chrome.exe 17141700x800000000000000047593Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-CreatePipe2021-09-14 08:50:59.553{C8F4C507-61C9-6140-9108-00000000F001}2256\mojo.2256.3920.15484067981633429150C:\Program Files\Google\Chrome\Application\chrome.exe 23542300x800000000000000047592Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.477{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A6D386416C29D9524AB863551452490C,SHA256=E6BFDFE0EA0B24B5E20617749DA6954C6F7B50B76A2F1B2590CF8579E9576A65,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047591Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.272{C8F4C507-61C9-6140-9108-00000000F001}2256ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Local State~RF62a26d.TMPMD5=22675B7F9B127CECFC2DA7FDE1125AC7,SHA256=206BDCCDA7E1AA9A18CB4F4E289C9374FD140B539AC3BEA7D38F844433119C40,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047649Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.873{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local65102- 354300x800000000000000047648Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.867{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local63680- 354300x800000000000000047647Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.860{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local60594-false152.195.132.116-443https 354300x800000000000000047646Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.849{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-51764- 354300x800000000000000047645Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.837{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local64284-false67.26.138.30-443https 354300x800000000000000047644Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.831{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local63798-false41.63.96.128-443https 354300x800000000000000047643Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.831{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61680-false87.248.118.23e2.ycpi.vip.deb.yahoo.com443https 354300x800000000000000047642Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.830{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local55865-false65.9.58.178-443https 354300x800000000000000047641Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.828{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local64873- 354300x800000000000000047640Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.827{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local64121- 354300x800000000000000047639Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.824{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51764- 354300x800000000000000047638Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.822{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local61578- 354300x800000000000000047637Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.820{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local60585- 354300x800000000000000047636Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.773{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local58228-false188.125.72.139media-router-brb71.prod.media.vip.ir2.yahoo.com443https 354300x800000000000000047635Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.741{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51637- 354300x800000000000000047634Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.555{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61110-false54.170.210.81ec2-54-170-210-81.eu-west-1.compute.amazonaws.com443https 354300x800000000000000047633Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.529{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local62387- 354300x800000000000000047632Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.426{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local52020-false52.208.96.136ec2-52-208-96-136.eu-west-1.compute.amazonaws.com443https 354300x800000000000000047631Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.403{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59698- 354300x800000000000000047630Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.333{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61008-false87.248.100.215media-router-fp73.prod.media.vip.ir2.yahoo.com443https 354300x800000000000000047629Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.209{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-65449- 23542300x800000000000000047628Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.693{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2DA674C68FA9865940BB35DF73C9C87,SHA256=36EA8C3A5A73449558A15456764B12F6A2DABF4ED79B4BF088612A8B8360CA97,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000025335Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:50:56.723{4A7D70D7-4C46-6140-CC00-00000000F101}2772C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-574.attackrange.local50899-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000025334Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:00.368{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2CFC10AFE89D1C6BD0B557F55DDD424,SHA256=5DD05EE3206AFCB4E43D1FD299967505239CE4EF2EDE2160637100DD396AA4FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047627Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.662{C8F4C507-618F-6140-6D08-00000000F001}3168ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\cra6argi.default-release\permissions.sqlite-journalMD5=C5A32AF5CDC590A891D1DEEBB5E45A19,SHA256=9B0BDAFB1B560DBB697FD1504E231F7DD4ECE0CB45D6544098D5981B09445052,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047626Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.546{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+a0d439|C:\Program Files\Mozilla Firefox\xul.dll+a0d35a|C:\Program Files\Mozilla Firefox\xul.dll+a0cf49|C:\Program Files\Mozilla Firefox\xul.dll+a090df|C:\Program Files\Mozilla Firefox\xul.dll+a093ec|C:\Program Files\Mozilla Firefox\xul.dll+b55c5a|C:\Program Files\Mozilla Firefox\xul.dll+2d9649|C:\Program Files\Mozilla Firefox\xul.dll+2d9554|C:\Program Files\Mozilla Firefox\xul.dll+2d933d|C:\Program Files\Mozilla Firefox\xul.dll+2d91d4|C:\Program Files\Mozilla Firefox\xul.dll+ba1993|C:\Program Files\Mozilla Firefox\xul.dll+ba2691|C:\Program Files\Mozilla Firefox\xul.dll+ba168d|C:\Program Files\Mozilla Firefox\xul.dll+ba15e2|C:\Program Files\Mozilla Firefox\xul.dll+b723b2|C:\Program Files\Mozilla Firefox\xul.dll+1a1b580|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda 10341000x800000000000000047625Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.543{C8F4C507-5C87-6140-B607-00000000F001}33727076C:\Windows\Explorer.EXE{C8F4C507-618F-6140-6D08-00000000F001}3168C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618b4|C:\Windows\System32\SHELL32.dll+62967|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+7c2cf|C:\Windows\System32\windows.storage.dll+7b04f|C:\Windows\System32\windows.storage.dll+7dfef|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047624Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.543{C8F4C507-618F-6140-6D08-00000000F001}31684684C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+37eb0|C:\Program Files\Mozilla Firefox\firefox.exe+37da6|C:\Program Files\Mozilla Firefox\firefox.exe+49380|C:\Program Files\Mozilla Firefox\firefox.exe+4907c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047623Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.543{C8F4C507-618F-6140-6D08-00000000F001}31684684C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+37eb0|C:\Program Files\Mozilla Firefox\firefox.exe+37da6|C:\Program Files\Mozilla Firefox\firefox.exe+49380|C:\Program Files\Mozilla Firefox\firefox.exe+4907c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047622Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.525{C8F4C507-5C87-6140-B607-00000000F001}3372288C:\Windows\Explorer.EXE{C8F4C507-618F-6140-6D08-00000000F001}3168C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618b4|C:\Windows\System32\SHELL32.dll+62390|C:\Windows\System32\TwinUI.dll+f54e1|C:\Windows\System32\TwinUI.dll+f5d4f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047621Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.525{C8F4C507-5C87-6140-B607-00000000F001}3372288C:\Windows\Explorer.EXE{C8F4C507-618F-6140-6D08-00000000F001}3168C:\Program Files\Mozilla Firefox\firefox.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+f5319|C:\Windows\System32\TwinUI.dll+f5d4f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 22542200x800000000000000047620Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.867{C8F4C507-61CB-6140-9408-00000000F001}4428edgecast-vod.yahoo.net0type: 5 cs929.wpc.lambdacdn.net;152.195.132.116;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047619Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.859{C8F4C507-61CB-6140-9408-00000000F001}4428dns-rjzc9hwev.sombrero.yahoo.net0type: 5 edge.gycpi.b.yahoodns.net;87.248.118.22;87.248.118.23;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047618Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.846{C8F4C507-61CB-6140-9408-00000000F001}4428v-cbwqxjvtsj.wc.yahoodns.net067.195.160.106;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047617Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.844{C8F4C507-61CB-6140-9408-00000000F001}4428vop-yahoo.secure.footprint.net067.26.138.30;8.248.138.157;67.27.157.1;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047616Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.841{C8F4C507-61CB-6140-9408-00000000F001}4428v-ag9e1orcdp.wc.yahoodns.net0115.178.9.9;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047615Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.838{C8F4C507-61CB-6140-9408-00000000F001}4428yahoovod.hs.llnwd.net041.63.96.128;41.63.96.0;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047614Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.837{C8F4C507-61CB-6140-9408-00000000F001}4428cerebro.edna.yahoo.net0type: 5 edge.gycpi.b.yahoodns.net;87.248.118.23;87.248.118.22;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047613Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.836{C8F4C507-61CB-6140-9408-00000000F001}4428d1vl8wytztdz.cloudfront.net065.9.58.178;65.9.58.173;65.9.58.40;65.9.58.189;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047612Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.834{C8F4C507-61CB-6140-9408-00000000F001}4428v-b9rh5is3h9.wc.yahoodns.net0119.161.16.77;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047611Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.755{C8F4C507-61CB-6140-9408-00000000F001}4428csp.yahoo.com0type: 5 media-router-brb1.prod.media.g03.yahoodns.net;188.125.72.139;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047610Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.728{C8F4C507-61CB-6140-9408-00000000F001}4428edge-mcdn.secure.yahoo.com0type: 5 edge.gycpi.b.yahoodns.net;87.248.118.22;87.248.118.23;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047609Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.540{C8F4C507-61CB-6140-9408-00000000F001}4428consent.yahoo.com0type: 5 real.rotation.guce.aws.oath.cloud;type: 5 prod-rotation-v2.guce.aws.oath.cloud;54.170.210.81;52.18.59.239;34.241.241.254;52.214.129.220;54.76.85.175;52.31.4.102;34.245.244.86;52.208.96.136;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047608Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.413{C8F4C507-61CB-6140-9408-00000000F001}4428guce.yahoo.com0type: 5 real.rotation.guce.aws.oath.cloud;type: 5 prod-rotation-v2.guce.aws.oath.cloud;52.208.96.136;54.170.210.81;52.18.59.239;34.241.241.254;52.214.129.220;54.76.85.175;52.31.4.102;34.245.244.86;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047607Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.315{C8F4C507-61CB-6140-9408-00000000F001}4428de.yahoo.com0type: 5 atsv2-fp-shed.wg1.b.yahoo.com;87.248.100.215;87.248.100.216;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047606Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.097{C8F4C507-61CB-6140-9408-00000000F001}4428www.yahoo.com0type: 5 new-fp-shed.wg1.b.yahoo.com;87.248.100.215;87.248.100.216;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047605Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:58.616{C8F4C507-61CB-6140-9408-00000000F001}4428yahoo.com098.137.11.163;74.6.231.21;98.137.11.164;74.6.231.20;74.6.143.26;74.6.143.25;C:\Program Files\Google\Chrome\Application\chrome.exe 354300x800000000000000047604Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.183{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local65449- 354300x800000000000000047603Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.114{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local65455-false87.248.100.215media-router-fp73.prod.media.vip.ir2.yahoo.com443https 354300x800000000000000047602Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.086{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local62126- 23542300x800000000000000047601Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.007{C8F4C507-61CB-6140-9408-00000000F001}4428ATTACKRANGE\AdministratorC:\Program Files\Google\Chrome\Application\chrome.exeC:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF62a54b.TMPMD5=4958343E4F3ACD33C9D8D700075A0E67,SHA256=451D298636596697D78EEE50B4A3553570EEE05C7CA4664A66D25843CCA7F331,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000047684Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.817{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local61558-false69.147.93.126-443https 354300x800000000000000047683Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.722{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local64719- 354300x800000000000000047682Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.714{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50904- 354300x800000000000000047681Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.714{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local49321- 354300x800000000000000047680Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.363{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local52192-false115.178.9.9e2.ycpi.aue.yahoo.com443https 354300x800000000000000047679Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.359{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local64473-false119.161.16.77-443https 354300x800000000000000047678Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.115{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local62361-false119.161.16.77-443https 354300x800000000000000047677Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.113{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local57526-false115.178.9.9e2.ycpi.aue.yahoo.com443https 354300x800000000000000047676Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.993{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local49721-false67.195.160.106o1.ycpi.gq1.yahoo.com443https 354300x800000000000000047675Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.898{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-58077- 354300x800000000000000047674Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.898{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-65102- 354300x800000000000000047673Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.874{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local53075-false23.213.161.68a23-213-161-68.deploy.static.akamaitechnologies.com443https 23542300x800000000000000047672Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.863{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E760CFE1124B5C3C303724B2187F62EA,SHA256=D5DFDE4698D2A5668FF21250D36A64277CF3105BA98989A80CF85710D126CD09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025336Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:01.383{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=788991A986C3BCAE0A75469E30CEE59E,SHA256=F9FEBBC91421A449C4F946F1A11062E9F5B43C160B82472C3C337FCCF12E6438,IMPHASH=00000000000000000000000000000000falsetrue 22542200x800000000000000047671Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.739{C8F4C507-61CB-6140-9408-00000000F001}4428ybar-b9rh5is3h9report.wc.yahoodns.net0200.152.173.200;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047670Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.737{C8F4C507-61CB-6140-9408-00000000F001}4428ybar-cbwqxjvtsjreport.wc.yahoodns.net069.147.93.126;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047669Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.726{C8F4C507-61CB-6140-9408-00000000F001}4428ybar-ag9e1orcdpreport.wc.yahoodns.net067.195.160.106;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047668Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.724{C8F4C507-61CB-6140-9408-00000000F001}4428ybar-mcdn-report.wc.yahoodns.net0115.178.9.9;C:\Program Files\Google\Chrome\Application\chrome.exe 22542200x800000000000000047667Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:50:59.878{C8F4C507-61CB-6140-9408-00000000F001}4428vop-yahoo.akamaized.net0type: 5 a759.w10.akamai.net;23.213.161.68;23.213.161.72;C:\Program Files\Google\Chrome\Application\chrome.exe 10341000x800000000000000047666Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.262{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+c0467b|C:\Program Files\Mozilla Firefox\xul.dll+bfd432|C:\Program Files\Mozilla Firefox\xul.dll+c02a70|C:\Program Files\Mozilla Firefox\xul.dll+c031cb|C:\Program Files\Mozilla Firefox\xul.dll+396c71|C:\Program Files\Mozilla Firefox\xul.dll+c03f99|C:\Program Files\Mozilla Firefox\xul.dll+c06f52|C:\Program Files\Mozilla Firefox\xul.dll+c039b6|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+c069c8|C:\Program Files\Mozilla Firefox\xul.dll+c06d2d 10341000x800000000000000047665Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.262{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+27c3fa8|C:\Program Files\Mozilla Firefox\xul.dll+27b52ec|C:\Program Files\Mozilla Firefox\xul.dll+bfe491|C:\Program Files\Mozilla Firefox\xul.dll+27ac2ad|C:\Program Files\Mozilla Firefox\xul.dll+c057d6|C:\Program Files\Mozilla Firefox\xul.dll+bfe95b|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+27ad51e|C:\Program Files\Mozilla Firefox\xul.dll+27ad2b4|C:\Program Files\Mozilla Firefox\xul.dll+c06a32|C:\Program Files\Mozilla Firefox\xul.dll+c007d9 10341000x800000000000000047664Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.262{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+c04bf0|C:\Program Files\Mozilla Firefox\xul.dll+27c138b|C:\Program Files\Mozilla Firefox\xul.dll+27b4476|C:\Program Files\Mozilla Firefox\xul.dll+bfe10a|C:\Program Files\Mozilla Firefox\xul.dll+27ac2ad|C:\Program Files\Mozilla Firefox\xul.dll+c057d6|C:\Program Files\Mozilla Firefox\xul.dll+bfe95b|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+27ad51e|C:\Program Files\Mozilla Firefox\xul.dll+27ad2b4|C:\Program Files\Mozilla Firefox\xul.dll+c06a32 10341000x800000000000000047663Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.262{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+c0467b|C:\Program Files\Mozilla Firefox\xul.dll+bfd432|C:\Program Files\Mozilla Firefox\xul.dll+c02a70|C:\Program Files\Mozilla Firefox\xul.dll+c031cb|C:\Program Files\Mozilla Firefox\xul.dll+396c71|C:\Program Files\Mozilla Firefox\xul.dll+c03f99|C:\Program Files\Mozilla Firefox\xul.dll+c06f52|C:\Program Files\Mozilla Firefox\xul.dll+c039b6|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+c069c8|C:\Program Files\Mozilla Firefox\xul.dll+c06d2d 10341000x800000000000000047662Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.247{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047661Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.247{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047660Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.247{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047659Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.247{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047658Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.220{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047657Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.220{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047656Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.220{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047655Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.220{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047654Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.220{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x800000000000000047653Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.220{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+27c3fa8|C:\Program Files\Mozilla Firefox\xul.dll+27b52ec|C:\Program Files\Mozilla Firefox\xul.dll+bfe491|C:\Program Files\Mozilla Firefox\xul.dll+27ac2ad|C:\Program Files\Mozilla Firefox\xul.dll+c057d6|C:\Program Files\Mozilla Firefox\xul.dll+bfe95b|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+27ad51e|C:\Program Files\Mozilla Firefox\xul.dll+27ad2b4|C:\Program Files\Mozilla Firefox\xul.dll+c06a32|C:\Program Files\Mozilla Firefox\xul.dll+c007d9 10341000x800000000000000047652Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.151{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+bee203|C:\Program Files\Mozilla Firefox\xul.dll+bed8a1|C:\Program Files\Mozilla Firefox\xul.dll+be54a3|C:\Program Files\Mozilla Firefox\xul.dll+beec50|C:\Program Files\Mozilla Firefox\xul.dll+faf709|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0caf6 10341000x800000000000000047651Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.151{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+bee203|C:\Program Files\Mozilla Firefox\xul.dll+bed8a1|C:\Program Files\Mozilla Firefox\xul.dll+be54a3|C:\Program Files\Mozilla Firefox\xul.dll+beec50|C:\Program Files\Mozilla Firefox\xul.dll+faf709|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0caf6 10341000x800000000000000047650Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.150{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+bee203|C:\Program Files\Mozilla Firefox\xul.dll+bed8a1|C:\Program Files\Mozilla Firefox\xul.dll+be54a3|C:\Program Files\Mozilla Firefox\xul.dll+beec50|C:\Program Files\Mozilla Firefox\xul.dll+faf709|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0caf6 354300x800000000000000047695Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.911{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-50808- 354300x800000000000000047694Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.911{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-52214- 354300x800000000000000047693Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.911{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-64293- 354300x800000000000000047692Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.906{C8F4C507-61CB-6140-9408-00000000F001}4428C:\Program Files\Google\Chrome\Application\chrome.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-158.attackrange.local50571-false200.152.173.200-443https 354300x800000000000000047691Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.881{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local52214- 354300x800000000000000047690Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.881{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local50808- 354300x800000000000000047689Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.881{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local64293- 354300x800000000000000047688Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.881{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51887- 354300x800000000000000047687Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.880{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local59222- 354300x800000000000000047686Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:00.880{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local60929- 23542300x800000000000000047685Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:02.869{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D4A9D75AA9FAC6FC74C3851442DCCF5,SHA256=96A0FAFF00C5333E9C364BE25C1637B015B706A492B2450BE60AA524D4788387,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025338Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:02.586{4A7D70D7-4BB8-6140-1300-00000000F101}368NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=B372C64FC9CF08AE1A3B51484AAECDBE,SHA256=A4992DE770F244DA9A85D8454F0CCD0EE53B75E5EA530CDA2F5645CB52C7A46F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025337Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:02.399{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36411852AB3F6402A263910BCE452A7D,SHA256=3C64EE75184F5035F7274DA8AC7563E0D1650BA8CED9437EF90CC4422A87E820,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047696Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:03.884{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=65DA5A6128E7D4F5BB0E38ACF83796E0,SHA256=2BC299D2441B1447718BCED5D4CA7A821DAFC7E3205BA4B5A97967B612071E77,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025339Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:03.399{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C446A489C683841BE1CD08014638BBA,SHA256=2C19B069378A810F5BFE4933463AA7F9B0BD586ADB9F86EA844205AE46788A3A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000047707Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.894{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9A1AA6EBE392D104BE1A299D6E9423D,SHA256=410D51672B6670E266D1DB7B5516854FD02FCC0659C33D3D45D5F74EE241A3ED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025340Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:04.415{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=420DF6D86CD96D553816769F4BA5F3C2,SHA256=A8CC5EE09A0AE93D7A01B530913DFE9D4A312FE14803723A945F5842AD0D15D4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047706Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.203{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59bc2|C:\Program Files\Mozilla Firefox\xul.dll+b73a63|C:\Program Files\Mozilla Firefox\xul.dll+b736f4|C:\Program Files\Mozilla Firefox\xul.dll+b73f2c|C:\Program Files\Mozilla Firefox\xul.dll+f73c12|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0bba0|C:\Program Files\Mozilla Firefox\xul.dll+f0ba15|C:\Program Files\Mozilla Firefox\xul.dll+f0b5a4|C:\Program Files\Mozilla Firefox\xul.dll+f0b049 10341000x800000000000000047705Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.203{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59bc2|C:\Program Files\Mozilla Firefox\xul.dll+b73a63|C:\Program Files\Mozilla Firefox\xul.dll+b736f4|C:\Program Files\Mozilla Firefox\xul.dll+b73f2c|C:\Program Files\Mozilla Firefox\xul.dll+f73c12|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0bba0|C:\Program Files\Mozilla Firefox\xul.dll+f0ba15|C:\Program Files\Mozilla Firefox\xul.dll+f0b5a4|C:\Program Files\Mozilla Firefox\xul.dll+f0b049 10341000x800000000000000047704Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.203{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+bee203|C:\Program Files\Mozilla Firefox\xul.dll+bed8a1|C:\Program Files\Mozilla Firefox\xul.dll+be54a3|C:\Program Files\Mozilla Firefox\xul.dll+beec50|C:\Program Files\Mozilla Firefox\xul.dll+f73b88|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0bba0 354300x800000000000000047703Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.927{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-58079- 354300x800000000000000047702Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.927{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-60658- 354300x800000000000000047701Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.927{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1-53domainfalse127.0.0.1-58078- 354300x800000000000000047700Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.897{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local58079- 354300x800000000000000047699Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.896{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local60658- 354300x800000000000000047698Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:01.896{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-158.attackrange.local51190- 10341000x800000000000000047697Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.012{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59bc2|C:\Program Files\Mozilla Firefox\xul.dll+b73a63|C:\Program Files\Mozilla Firefox\xul.dll+b736f4|C:\Program Files\Mozilla Firefox\xul.dll+b73f2c|C:\Program Files\Mozilla Firefox\xul.dll+f73c12|C:\Program Files\Mozilla Firefox\xul.dll+1a1b54f|C:\Program Files\Mozilla Firefox\xul.dll+b78344|C:\Program Files\Mozilla Firefox\xul.dll+fca4c4|C:\Program Files\Mozilla Firefox\xul.dll+f36457|C:\Program Files\Mozilla Firefox\xul.dll+2cbfda|C:\Program Files\Mozilla Firefox\xul.dll+ea7e38|C:\Program Files\Mozilla Firefox\xul.dll+ea7972|C:\Program Files\Mozilla Firefox\xul.dll+2b4572|C:\Program Files\Mozilla Firefox\xul.dll+1ab7d5f|C:\Program Files\Mozilla Firefox\xul.dll+f0bba0|C:\Program Files\Mozilla Firefox\xul.dll+f0ba15|C:\Program Files\Mozilla Firefox\xul.dll+f0b5a4|C:\Program Files\Mozilla Firefox\xul.dll+f0b049 10341000x800000000000000047719Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:05.936{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+27c3fa8|C:\Program Files\Mozilla Firefox\xul.dll+27b52ec|C:\Program Files\Mozilla Firefox\xul.dll+bfe491|C:\Program Files\Mozilla Firefox\xul.dll+27ac2ad|C:\Program Files\Mozilla Firefox\xul.dll+c057d6|C:\Program Files\Mozilla Firefox\xul.dll+bfe95b|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+27ad51e|C:\Program Files\Mozilla Firefox\xul.dll+27ad2b4|C:\Program Files\Mozilla Firefox\xul.dll+c06a32|C:\Program Files\Mozilla Firefox\xul.dll+c007d9 10341000x800000000000000047718Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:05.910{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b5c4e8|C:\Program Files\Mozilla Firefox\xul.dll+19a2e8e|C:\Program Files\Mozilla Firefox\xul.dll+166f362|C:\Program Files\Mozilla Firefox\xul.dll+19ccb3c|C:\Program Files\Mozilla Firefox\xul.dll+9ebb5f|C:\Program Files\Mozilla Firefox\xul.dll+26b8e|C:\Program Files\Mozilla Firefox\xul.dll+19d5d8|C:\Program Files\Mozilla Firefox\xul.dll+19c48f|C:\Program Files\Mozilla Firefox\xul.dll+42102ba|C:\Program Files\Mozilla Firefox\xul.dll+427c355|C:\Program Files\Mozilla Firefox\xul.dll+427d173|C:\Program Files\Mozilla Firefox\xul.dll+1ef1143|C:\Program Files\Mozilla Firefox\firefox.exe+5c4d|C:\Program Files\Mozilla Firefox\firefox.exe+1bb98|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 23542300x800000000000000047717Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:05.907{C8F4C507-495A-6140-7B00-00000000F001}3640NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=47D0FAB31A080BCD2DDC45389306AE6C,SHA256=9FC6F630D11E33C50158DA39F673F46C74C836F8E084BFE19C43DF8C6C6B0578,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000025344Microsoft-Windows-Sysmon/Operationalwin-host-574.attackrange.local-2021-09-14 08:51:05.420{4A7D70D7-4C4C-6140-D500-00000000F101}4060NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E04E2FE69F338F84291E7D45ED2603E,SHA256=D0318B1A41FF9E644B7AB7D3B92ED1AEFA7A8D5CC1606F0C8D5C6883EABB309E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000047716Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:05.715{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+27c3fa8|C:\Program Files\Mozilla Firefox\xul.dll+27b52ec|C:\Program Files\Mozilla Firefox\xul.dll+bfe491|C:\Program Files\Mozilla Firefox\xul.dll+27ac2ad|C:\Program Files\Mozilla Firefox\xul.dll+c057d6|C:\Program Files\Mozilla Firefox\xul.dll+bfe95b|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+27ad51e|C:\Program Files\Mozilla Firefox\xul.dll+27ad2b4|C:\Program Files\Mozilla Firefox\xul.dll+c06a32|C:\Program Files\Mozilla Firefox\xul.dll+c007d9 10341000x800000000000000047715Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:05.715{C8F4C507-618F-6140-6D08-00000000F001}31684016C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\xul.dll+1b5281|C:\Program Files\Mozilla Firefox\xul.dll+9e9474|C:\Program Files\Mozilla Firefox\xul.dll+b7d641|C:\Program Files\Mozilla Firefox\xul.dll+b59893|C:\Program Files\Mozilla Firefox\xul.dll+b59a47|C:\Program Files\Mozilla Firefox\xul.dll+b7d55f|C:\Program Files\Mozilla Firefox\xul.dll+bef0a5|C:\Program Files\Mozilla Firefox\xul.dll+3a4121|C:\Program Files\Mozilla Firefox\xul.dll+3a3ca4|C:\Program Files\Mozilla Firefox\xul.dll+3a3b48|C:\Program Files\Mozilla Firefox\xul.dll+27c3fa8|C:\Program Files\Mozilla Firefox\xul.dll+27b52ec|C:\Program Files\Mozilla Firefox\xul.dll+bfe491|C:\Program Files\Mozilla Firefox\xul.dll+27ac2ad|C:\Program Files\Mozilla Firefox\xul.dll+c057d6|C:\Program Files\Mozilla Firefox\xul.dll+bfe95b|C:\Program Files\Mozilla Firefox\xul.dll+39647b|C:\Program Files\Mozilla Firefox\xul.dll+c00578|C:\Program Files\Mozilla Firefox\xul.dll+27ad51e|C:\Program Files\Mozilla Firefox\xul.dll+27ad2b4|C:\Program Files\Mozilla Firefox\xul.dll+c06a32|C:\Program Files\Mozilla Firefox\xul.dll+c007d9 22542200x800000000000000047714Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.249{C8F4C507-618F-6140-6D08-00000000F001}3168www.google.com02a00:1450:4001:812::2004;C:\Program Files\Mozilla Firefox\firefox.exe 10341000x800000000000000047713Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:05.491{C8F4C507-618F-6140-6D08-00000000F001}31684684C:\Program Files\Mozilla Firefox\firefox.exe{C8F4C507-6191-6140-6E08-00000000F001}6744C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\Mozilla Firefox\firefox.exe+37eb0|C:\Program Files\Mozilla Firefox\firefox.exe+37da6|C:\Program Files\Mozilla Firefox\firefox.exe+49380|C:\Program Files\Mozilla Firefox\firefox.exe+4907c|C:\Windows\SYSTEM32\ntdll.dll+7f60d|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x800000000000000047712Microsoft-Windows-Sysmon/Operationalwin-dc-158.attackrange.local-2021-09-14 08:51:04.239{C8F4C507-4948-6140-2E00-00000000F001}3056C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalse