23542300x800000000000000040449Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:22.020{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D82CFD8C62008F42035B3D1BB86229CB,SHA256=B24AF0747285F1763609201DE3BABE019897060A5EE5F35A4F542CBAA9FDFB49,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028204Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:22.209{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=168B6AC749E6CB1514B5EBC6B65573D6,SHA256=04875C2B4B678468A347469EFE06A850E6F6F7D940722017E1AB8CD0DD92D315,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028205Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:23.240{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0906FCA274EDDB222C9F8289661A9824,SHA256=43134C594BC5188E9FCE192C3BDF5DFDF4C321564A8F2ABB26B02A7C33E1CDB5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040450Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:23.051{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9DE10B960ABF568FE37B47CCC7E48894,SHA256=4E5C2B364992848E33603833ABD32A2675DDA4F3F901E5FE8D3E3E18CF24C1E3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028207Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:21.691{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51085-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028206Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:24.255{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8DD64FEE06B73BA42B83597D4446E65E,SHA256=6D604179B05DB757339A61198B843F0E798F340F3ACADCF58915F5D5F2B73C22,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040451Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:24.082{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6E8BB5867148DE3C0573DFE2053BCE89,SHA256=726EB69BCC423E5C5AE1EE37CA3EE081D92D088447E86236A5EF367493F29766,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040453Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:23.021{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58928-false10.0.1.12-8000- 23542300x800000000000000040452Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:25.098{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=250DAB43C74820A8FBEFFCF7C88ACD5C,SHA256=344146D546EEB3E3B2E36B7055E518F3A2783CFB86208649B5305D291337774C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028208Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:25.256{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DBFA1F0984B58428E5AE9ADDEB425B1,SHA256=316A8F6E66655B13A3B972C6A3BC252038C4BFFA8EBBA87C0B69CF4112F8398B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040454Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:26.114{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4FCBCFE3A8A7196A9738932E1913C950,SHA256=EB499B48C8E9DF0EE4C377742518B07C1980B63C095662005807B0653BACC180,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028209Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:26.271{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EE27D6E85B33C4529FE2A010FE26E90,SHA256=2F02B07DAC33A743AEAD0DE8F9905BEDA5B2A90418897809A8A7261E68948084,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028210Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:27.299{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AB708C9AB1C3AB6C299FF699ECF0382,SHA256=C17C61850E826932F4E85B4FFBB32674C81707F20CD101DF53C66BDBA491DC2C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040455Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:27.140{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2E186328C2B17AEB12FA1117019045F,SHA256=69421D72DB752EEB13CFF9FC7BCCA366E9542EE6F567C9C0DE98A6BB22AD08B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028211Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:28.330{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85E72EB1D8C5FEF7A084D31D346F044E,SHA256=244C194A961C0123154ECDC70FBA48F020A0AF8811C5F5138B9E048966CC0FAD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040456Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:28.171{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=480A95DC97C8B7EC9E796DA19B6477C8,SHA256=59EC4E85FB7B314BC1B734C1AF99C4B354F3C28CF37AA48511C3960115D123F9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028213Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:29.361{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8AC842E7C089F81B29759421E7530F0B,SHA256=24431FBBFFF065DFD04B24899388DFA550ED80C0C8343EAAF494E4645610299B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040457Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:29.187{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB626D74C4B517FFB836B9EC6F1D78D2,SHA256=BB484A8E6BBEE6063BE90342839052DA43FC640CED2764E7A53C853AC2C32DA8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028212Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:27.688{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51086-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000040459Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:29.045{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58929-false10.0.1.12-8000- 23542300x800000000000000040458Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:30.202{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=524C57B296DAB221D40BA70FFFE3FA0B,SHA256=414B39BA6CCCCD35963227D28E6C6939DF5041C80DC95BE308085CB400D6E56A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028214Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:30.377{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A460B853CB0D68CB061C726923A83C6,SHA256=6D4E68CCC490CD2675283013CAFD6CEE1880FC130BD4CE384E2324C21B525759,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028242Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77E7-616D-B106-000000000502}2472C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028241Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028240Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028239Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028238Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028237Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028236Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028235Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028234Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028233Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028232Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-77E7-616D-B106-000000000502}2472C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028231Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.892{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77E7-616D-B106-000000000502}2472C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028230Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.893{6F8252D3-77E7-616D-B106-000000000502}2472C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000028229Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.658{6F8252D3-77E7-616D-B006-000000000502}31883344C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028228Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.424{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=63B1D59DB4F2E90287703A60AD4D43EA,SHA256=6CB29FDF529A022BECFEE86C7A0C058BB9CFDD0240A61ABE7963E613CD6D12F3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040460Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:31.234{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7161C4CBC439D9DCBEFDDF6B8D504139,SHA256=151DB3D0810A242692044A0973F7818F881F26176CECE7153FCDDAE14B8BAC26,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028227Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77E7-616D-B006-000000000502}3188C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028226Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028225Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028224Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028223Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028222Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028221Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028220Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028219Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028218Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028217Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-77E7-616D-B006-000000000502}3188C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028216Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.392{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77E7-616D-B006-000000000502}3188C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028215Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:31.393{6F8252D3-77E7-616D-B006-000000000502}3188C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000028258Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77E8-616D-B206-000000000502}2916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028257Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028256Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028255Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028254Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028253Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028252Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028251Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028250Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028249Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028248Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-77E8-616D-B206-000000000502}2916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028247Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.564{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77E8-616D-B206-000000000502}2916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028246Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.565{6F8252D3-77E8-616D-B206-000000000502}2916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028245Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.486{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=49FD0EA9A4F219966BB6D58F18C5F2A1,SHA256=39251D312418A453F6CBD93BC5229A4BF9431E9E65A799E1DC03195AED1A3A54,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028244Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.486{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=69F709EC8364906A732B02887B02A0CE,SHA256=D5E4D03A85B1D1419E81B38CAC8DBD15598F4F26BD3F280D027AEEA9CC2E0DF6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028243Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.455{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=90CF90B3325F8460541ABCDD5CEE55E7,SHA256=E5B5523CDFC3B7713C7D863C38C6E753D655F3DA68C2390AE67DA3210C23CC72,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040461Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:32.234{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDBAE878639163918BAA5D74FB22AA04,SHA256=00FEDD6C2A638A46140A15EF9E13A8572DEEB8713D9A59A60E7956AF14F24F87,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028274Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.830{6F8252D3-77E9-616D-B306-000000000502}26523952C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028273Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=49FD0EA9A4F219966BB6D58F18C5F2A1,SHA256=39251D312418A453F6CBD93BC5229A4BF9431E9E65A799E1DC03195AED1A3A54,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028272Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028271Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028270Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77E9-616D-B306-000000000502}2652C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028269Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028268Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028267Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028266Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028265Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028264Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028263Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028262Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-77E9-616D-B306-000000000502}2652C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028261Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77E9-616D-B306-000000000502}2652C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028260Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.643{6F8252D3-77E9-616D-B306-000000000502}2652C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028259Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:33.455{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=557C9EA0179154DB2CD69CA6BD874397,SHA256=AD1EAD135D9EFC3A0656AAB312053C566B35FFF42963F9B2EF18D60F5476A8F3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040469Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:31.904{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58930-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000040468Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:31.904{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58930-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000040467Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:33.265{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A604225B1A6D9D8A563962F677567BA5,SHA256=CE772D4B00FEDC42A6C9CFD1EBE9A20806D6423EF2065F59D2936ABA342C120D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040466Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:33.093{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1500-000000000402}1248C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040465Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:33.093{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1500-000000000402}1248C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040464Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:33.093{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1500-000000000402}1248C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040463Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:33.046{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C8C65DF0ED8F379AC949AD6160CEC9F4,SHA256=6D6E786532B6ACD5C0CB3D10FBB901F3A8A932A1C91173E41492DB1E199E7248,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040462Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:33.046{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=95125152DF68130E04D405AA82B57B35,SHA256=1EFA9DFDAEE2BEE74E039E9FB8251F25E2D6FA78D8FA82238F775BA4C3F9CCAE,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040489Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.937{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040488Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.937{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040487Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.937{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040486Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.937{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA4-616D-0100-000000000402}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96ef2|C:\Windows\system32\kerberos.DLL+793e4|C:\Windows\system32\kerberos.DLL+1443f|C:\Windows\system32\lsasrv.dll+2e0d1|C:\Windows\system32\lsasrv.dll+2c294|C:\Windows\system32\lsasrv.dll+317e9|C:\Windows\system32\lsasrv.dll+2f147|C:\Windows\system32\lsasrv.dll+2e0d1|C:\Windows\system32\lsasrv.dll+16cad|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e 10341000x800000000000000040485Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040484Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040483Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040482Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040481Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040480Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040479Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040478Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040477Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040476Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040475Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040474Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040473Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040472Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040471Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.827{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040470Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.280{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD85EEAC63021DF70197B83A9C29FC53,SHA256=5581DA520BFB58CFCD5AE264041FE1E87D8E7EEECBBE32C0C02473D6D46BE878,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028291Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.955{6F8252D3-77EA-616D-B406-000000000502}38323628C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028290Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77EA-616D-B406-000000000502}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028289Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028288Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028287Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028286Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028285Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028284Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028283Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028282Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028281Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028280Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-77EA-616D-B406-000000000502}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028279Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.767{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77EA-616D-B406-000000000502}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028278Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.768{6F8252D3-77EA-616D-B406-000000000502}3832C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028277Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.658{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1E209B434B2134D1DD11789E3B8BE7CF,SHA256=30A07C23572EFCA6488EBD5B22BDEAB2E9460EDB0D3BD0EB22FDF1C51619796F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028276Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:32.750{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51087-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028275Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:34.486{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F2BA28B0FE6579835C65B84063F014B,SHA256=723C33B3AC4DB54E3890F11147EFDF0FEC235AC0F6D9CA2BB1451943762752B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028307Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.814{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=63AFCFC4AB92612A5E02D9855EA67573,SHA256=AF6D36E48B1D861ED4489CA8B7A6A8E62E3AF6C8DF5E6B887960EB5443608831,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028306Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.642{6F8252D3-77EB-616D-B506-000000000502}30123724C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028305Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.533{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F161A78748F4CBFEAFE1E2B7430991D9,SHA256=008BA1EB3BF74208FC8BFCF2A3A5551BED15FFC6920BA61B4FD8239A92CAB0A4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040491Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.076{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58931-false10.0.1.12-8000- 23542300x800000000000000040490Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:35.312{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50E09DAF62EE4BFA618DFDDE963D9EFB,SHA256=9C66F561EB311DDCD63EB5DD5D8A49D776085AFE58642D5F09943E9B8001F335,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028304Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77EB-616D-B506-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028303Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028302Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028301Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028300Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028299Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028298Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028297Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028296Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028295Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028294Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-77EB-616D-B506-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028293Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.439{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77EB-616D-B506-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028292Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:35.440{6F8252D3-77EB-616D-B506-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028321Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.549{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9776250728F98B2EC9DCFDE7DC0712A5,SHA256=7E00F0F85965CC0BB3DB761C00033D064E276D0B5C3F1A1ACEC4A36434A39519,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040499Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.814{8D4DD44E-5BA4-616D-0100-000000000402}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58934-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local445microsoft-ds 354300x800000000000000040498Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.814{8D4DD44E-5BA4-616D-0100-000000000402}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58934-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local445microsoft-ds 354300x800000000000000040497Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.721{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-185.attackrange.local58933-false10.0.1.14win-dc-185.attackrange.local389ldap 354300x800000000000000040496Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.721{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58933-false10.0.1.14win-dc-185.attackrange.local389ldap 354300x800000000000000040495Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.707{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58932-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000040494Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:34.707{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58932-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 23542300x800000000000000040493Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:36.343{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98F404499A48D7C3EF1580EB94564E07,SHA256=6F38061B1E0B2F58CAAEC4E0ECF40587C29622690136511090B87121B56E17A4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028320Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-77EC-616D-B606-000000000502}3744C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028319Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028318Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028317Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028316Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028315Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028314Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028313Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028312Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028311Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028310Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-77EC-616D-B606-000000000502}3744C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028309Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.111{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-77EC-616D-B606-000000000502}3744C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028308Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:36.112{6F8252D3-77EC-616D-B606-000000000502}3744C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040492Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:36.062{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C8C65DF0ED8F379AC949AD6160CEC9F4,SHA256=6D6E786532B6ACD5C0CB3D10FBB901F3A8A932A1C91173E41492DB1E199E7248,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028323Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:37.564{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0CB5DBB94E2F8D823B67B75A6C565107,SHA256=93331CC095A189697037B83D1FBC08F3B3CFC8744D57DD7B297F07C7041900E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040500Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:37.374{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B438C8946BF684B14B1625DD70DCA05D,SHA256=60875742F25087803DF2E7568422E1C2E4E61173FD9760673161021D25C35F77,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028322Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:37.158{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A663CCA4146CA479E49EF9607D5E3AA8,SHA256=39E8B85034263663FB52D56247FEEF91C15EAD56A9FBEA6780318988CDA0ECFD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028324Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:38.580{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5612BB2089BBFA88B9D333830BA513AB,SHA256=6B6B6C18C1E1386A6A42C94AEA99F95DCC278BD38E988000AC9EE4F9958F4FB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040501Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:38.468{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67C1997850CBFA0E91CFBA037A0EFE05,SHA256=1E43414B4714BADD3511D6F4D9C7F7C3DBB61DC2A45F2506B9538F216C92CA0E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040502Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:39.702{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4CF51DB0B929282A1ABD7F6D45A5EDC5,SHA256=B08CCECE05052E76B1C71BAAFBF3CBC2DF4B7C0757FEA65E36EAEE17A277A301,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028326Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:39.586{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF5D6D5FA67D3B8370E7DADC0B908E58,SHA256=3A0A270DFBD4F6669C472B50078477B29669CC0900AD2AD83A71597B281702C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028325Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:39.427{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-108MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040503Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:40.734{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=125CA498DA2A93D54FC99FDD87660B11,SHA256=949733019B82005EB30F00F35661988C4B1E184873DD13742815A2CB80BEE81A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028328Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:40.599{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EF8EF5C5DBB9DE78579F888BA788E005,SHA256=5A5BD997D3F004C19916C40314DF8BC4FEB56ACD009A10A66E5FD0AA839B2BF2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028327Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:40.429{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-109MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040504Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:41.780{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=357CA08AB220F38248077CCD332E005D,SHA256=FFC0FB53BD506E8142E6059CDF59C28D9C4613309BA5309889D2EB283D23B48F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028330Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:41.601{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D68ECC52FC633729965B6874BF2000B1,SHA256=64F1C51565AFD01E533B408E7C77C719C024FCCDF42FFDC860A42EF5EE8BABC3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028329Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:38.767{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51088-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028331Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:42.617{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2304E8737906CA93379774DC8C2349F3,SHA256=2EFC277653292C2D70DA1C4560E7D0CFA7E67DC08FD06D46E35D78580ABFD51A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040506Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:42.796{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0536D61D64C33C82A9B30C3CFBBB7D1,SHA256=4F09CF2E1A3AFDD34078A72D8C63340D61C545339237A703E10113E2E69FCE39,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040505Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:39.982{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58935-false10.0.1.12-8000- 23542300x800000000000000040507Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:43.812{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98BD0E6DB21327DABEBE811685A3BD45,SHA256=D9A97CCD7B8D387F3AA0C81E810DBB2E691918AC5AEB7155329232C2B38B06E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028332Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:43.632{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C4E6966F1AEE03E4BACD50AAC161BF7,SHA256=0D023D29652AD64AB1DBCBD2393BDD1F26437D3664090AC878359178CA1CA239,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040508Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:44.843{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1642AA38DA3AD180EDA2699B876D8B12,SHA256=EABB62D8CE5739752299188FFBBD5022167D5ED43B2782809D9FEA8588E6B3AF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028333Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:44.648{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15326944A319B63B4A76DAF226768CBC,SHA256=7C11C699DB71ECBDDA8BD7A9096A93C4F3D5AC52EFE617074C11B7EA384E4EAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028334Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:45.664{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=198E0176816C49397E82E6000FC3C1B7,SHA256=52344E2DBAF26A82CA864DF5EEB95A9028E91BFE936D9EED8EA08A335310335C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040509Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:45.859{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4365509FB2F5A5550352662D0F6E8F82,SHA256=4F50A306B5D73152EB8C0D37EB8C35689FC0EEE52387748CE7B278043F63D170,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028335Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:46.679{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0962E1A9E196565495C9B98EF1DD1CCF,SHA256=1381C5CDEAE5F055C4AD4E355B45CEE41028DD4633CFF1ADF7DBDF85D29F7781,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040512Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:46.874{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=54F564E23E2B475C428DCDDCEE9EFE99,SHA256=08C87B92943B9095EEB2CD34B731E9B80C3B47D1E8C5EBEA25E3A1FE2ECFE90F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040511Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:46.655{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=47E60DB110EF299E91B9CB818C32118F,SHA256=5925BCB5E2CAE9A956A8902FAE35D65DACA4571C511C8BE6011BBCF8FCE58EC8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040510Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:46.655{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D2D14E88B1EBBDEDDD59D987D7BCD3C,SHA256=85D30CC0F3771F7E6182174CC4616A54A352AEB97465C6AF9FB7B043CCEB9291,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040517Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.890{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6CB6DE768C71485EB4FEF9AC4BB4512C,SHA256=FE6D8E03AE0ACCBE850343D18C7670C73507BE31737BEEBED0E380A3C5EF7996,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028337Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:44.724{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51089-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028336Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:47.689{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03C4FDE11E4EF8431E28C5F7360B8627,SHA256=80C37E15E15F2879B76BE59B560E77316D1773F0DF2BD3B87498A03C48DE8F07,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000040516Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:34:47.499{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\60E60F09-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_60E60F09-0000-0000-0000-100000000000.XML 13241300x800000000000000040515Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:34:47.499{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\B282E4C4-BB5A-46C5-9F10-A3714310BED4\Config SourceDWORD (0x00000001) 13241300x800000000000000040514Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:34:47.499{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\B282E4C4-BB5A-46C5-9F10-A3714310BED4\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_B282E4C4-BB5A-46C5-9F10-A3714310BED4.XML 354300x800000000000000040513Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:45.092{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58936-false10.0.1.12-8000- 23542300x800000000000000040521Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:48.983{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E1C98FBFAD8E776C37673FD4C09EDF0,SHA256=AE4A94E34083634EE2C269690F14D368F6D5070C12BAF37F7D44A04926DB614A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028338Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:48.705{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C8450526CA8985F88DD315070BF9024,SHA256=ACC4E10CDBA42D8C5BE94619B7A07AAFDDA541D4748505CB544CF3D2FCAE4979,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040520Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:48.530{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=47E60DB110EF299E91B9CB818C32118F,SHA256=5925BCB5E2CAE9A956A8902FAE35D65DACA4571C511C8BE6011BBCF8FCE58EC8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040519Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.359{8D4DD44E-5BA9-616D-0D00-000000000402}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58937-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 354300x800000000000000040518Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.358{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58937-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 23542300x800000000000000028339Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:49.720{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CAF83A8154EDA9A8052278492121C5E8,SHA256=CA205CBB8E5DC1F287A04513958D1D08B00216B74455CA74977EC055CA653209,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040525Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.393{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58939-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000040524Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.393{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58939-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000040523Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.380{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58938-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000040522Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:47.380{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58938-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 23542300x800000000000000028340Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:50.736{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A7A7F7F7951E63A436A3E7467941232,SHA256=EB70F186903D6CACEC46FC2E167D6832C27D976BA153EDCE708A26EDDDC9D22A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040526Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:49.999{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8932ED7A25338E54A66A1B66EFE6609D,SHA256=A60F87D68BB0F6CFE62DD77EB0F3EB53C62EDC74BFA48411607E9237D1119067,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028342Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:51.783{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=4143233949AA62718AA63D2860FB2700,SHA256=C50112E8D515BA0F6C67162A53616E36A765F63E1340ED4A160DF16F36B6A50E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028341Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:51.752{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=10C021CCF09E595EC3C4F90143EFDC70,SHA256=54D546F8786A86BBA79940E69FE99816103DB850ADED0B9AC225E0517E5FABAE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040528Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:50.108{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58940-false10.0.1.12-8000- 23542300x800000000000000040527Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:51.030{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF047D237CAF58B0E17148D64BC2C9B6,SHA256=8FB710EABE2D44B335704A1E39A2B4FDB1FB52A1F87061CFF0D69BFA8ED8B3B4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028343Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:52.767{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC9A494C00A78B76FAE74BE16EDF783C,SHA256=FCD0DA39ACEDC50FD4FA461ECADA282A2AF636E1CE53BE70BD1D7D7F29BFCCEC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040529Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:52.233{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A30B0EF832DB5CD3CF340CDB0EECCC11,SHA256=0FEF625F190C7110CC4DF157EB6331046670200683803D91F79656F48CB16E52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028357Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:53.814{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FBB3A03941D0DF5EAB9DE42DD623B222,SHA256=3040768B2AABE2C6CB402F35C90E2F075A7228C5FE178E7A9E532AAB787CD2EF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040530Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:53.249{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC2FBC1F29ED96957BCB259836366C0F,SHA256=9691DB8814D85586D5E51DE22A5F1A2575C47786A92BFC1BEE942EDD5A2634CD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028356Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:53.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBA-616D-1600-000000000502}1240C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028355Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:53.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBA-616D-1600-000000000502}1240C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028354Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:53.767{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBA-616D-1600-000000000502}1240C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 13241300x800000000000000028353Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000028352Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0066a3b2) 13241300x800000000000000028351Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7c41c-0x8c7c3bf2) 13241300x800000000000000028350Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7c424-0xee40a3f2) 13241300x800000000000000028349Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7c42d-0x50050bf2) 13241300x800000000000000028348Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000028347Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0066a3b2) 13241300x800000000000000028346Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7c41c-0x8c7c3bf2) 13241300x800000000000000028345Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7c424-0xee40a3f2) 13241300x800000000000000028344Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:34:53.298{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7c42d-0x50050bf2) 23542300x800000000000000028359Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:54.830{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0D1F08B8C29DF335778E8662FB8C5FA,SHA256=FB829D1E386127B39007C5F83AFD7EAB8D3E3D6977D943DF34F3D6DD50F931B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040531Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:54.280{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B423643112D47EE7F3950155DBB168AB,SHA256=DE1DE1D72CA91ABCAA3937A55513CAD4BA001E422593A232D2C75B788C830E8A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028358Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:50.656{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51090-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028360Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:55.877{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=952839625F5EA815FFB85F8E2A9B4EF7,SHA256=9AB6E40162C6CACE0F682D9C63A44FAF93259475B0365A2D67C931A77A690179,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040532Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:55.311{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=34EC3F34C319E00EE488276DC2CC03FC,SHA256=DF7DDC6420E06B4BF83D0EE34F1A5C54D87B1581BD55CF001AD8E3F66E75AD61,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028361Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:56.892{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=19DEFB0E7B6BD665364E2FC2FF553358,SHA256=C52653E5B116DA7371FF7409D08B5FCA78BAF55780A92E4A4C2DD3AA3B5447F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040533Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:56.327{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3B7CE89F58064D7E3CE4EFC5AA30108B,SHA256=46B655513B48B758E293FE87485CABDE37AB2BAF63D7A6F629363365D9CF42F1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028362Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:57.908{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=26CA4DC984C9EA51354555E778AE09DD,SHA256=3DACB42D0F19A94563D1EC4CA9793262209DE787980C7F8BCABB5645651E1E7D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040535Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:56.061{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58941-false10.0.1.12-8000- 23542300x800000000000000040534Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:57.343{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EA2B273A60070D50CCA00E9CB1594C8,SHA256=26C6CCB3CFFD2E7F6895E6AC1A566B2682705FDD4E4BB2F727EBABA3D3571434,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028364Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:58.923{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6EA45687B396714C12FBE484E56AE655,SHA256=A01AA6C808F7A7A9ED94427B89062D496C6EC3C724E796DDE4A89C784AA9099F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040536Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:58.405{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=68D866F2C8568C3DA7BD874DD4310AEA,SHA256=82D7F9924AF6B36FA27483E2C65CEF616D57C84082110508E42D0A1E6615745A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028363Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:55.765{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51091-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028365Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:59.955{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E45EAD79F835AB5883C8FB9438882E4C,SHA256=7658D874147D79A0304CF5800C2D13041C6799D25D692398C5650C05AD89E2F0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040537Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:34:59.436{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=343DC651E41CF6CF9F97D30DBD5A401B,SHA256=C89C31C710D783C1ED237B41C3CC3CFC084880BAFB4C38B42CBD8976E93EEAA4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028367Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:00.986{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B475BA2719ECF8F972482BAC28F7B61C,SHA256=328012053422D3E6EA957A1F827FD4642134FE344546943FB8922F817BCDB347,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040538Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:00.452{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=905366F190631EA30B9D9BF37FD92471,SHA256=A7CBEF8FD0DDEB6AB5657545FE65DC0A6E80A1C48AC56DB10A9CDB611FB4BB9C,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000028366Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:35:00.080{6F8252D3-5DBA-616D-1200-000000000502}288C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7c424-0xf2b91ac4) 23542300x800000000000000040539Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:01.499{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C14444DC99DB6DFA655A8240F1818C79,SHA256=6A2DF3AC3621F7272B95D2A392423C7BA9C8F9CFC39DB3FB6DF641F0B4EEBE12,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028368Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:34:59.623{6F8252D3-5DBA-616D-1200-000000000502}288C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.15win-host-470.attackrange.local123ntpfalse169.254.169.123-123ntp 23542300x800000000000000040541Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:02.671{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=8BDA937F301A9C536B499C8789FEF659,SHA256=78C745ECB4A6E08FA49A4C9B10BD413A8EB6E624437B1A7ECBF7B1E8E3721D30,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040540Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:02.515{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1BB5F49D8C6C355E45E321FFFCC44481,SHA256=9B47D277EBA05DFCC744E879DE60F30B15A4D789AC5A1F7F7A65B0CA428CA057,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028369Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:02.017{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E90A302BCCCC711DD8D227ACF7915589,SHA256=09AECC544E61A0901E4EB175B6569BF4B26D9651E0F8F83A51AD3DE4D178925A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040542Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:03.530{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D6D10C1C75E47C15CF025874422D6ECF,SHA256=E690026E3BB910724FEE18FFDDC25D4D4BD08A9E5F3852F67CDDA0EDC7455DB8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028372Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:01.379{6F8252D3-5DB7-616D-0100-000000000502}4SystemNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.255ip-10-0-1-255.eu-central-1.compute.internal138netbios-dgmfalse10.0.1.15win-host-470.attackrange.local138netbios-dgm 354300x800000000000000028371Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:01.379{6F8252D3-5DB7-616D-0100-000000000502}4SystemNT AUTHORITY\SYSTEMudptruefalse10.0.1.15win-host-470.attackrange.local138netbios-dgmfalse10.0.1.255ip-10-0-1-255.eu-central-1.compute.internal138netbios-dgm 23542300x800000000000000028370Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:03.095{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F6A1748117C0E84D79FDC29BE2D40F5,SHA256=33EB2ED97C33544D2DDF3F120BD3E47B10AD9F23ED7CC91CDC2FCC60AFDE67EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040544Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:04.530{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FF719CC80E0F6445CE522736DBE8514F,SHA256=47826C430F579CC2BC3AA11D36E653BD89F31536B360446390094BCD4EF62B2F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028374Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:01.796{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51092-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028373Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:04.142{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F121320B60DB3025E61B6F8C59FB5D2C,SHA256=3FCA617AA347BEF3BE9AE6E99C26E394E26948DF5F8998D5A0D9BFA6905BD325,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040543Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:01.984{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58942-false10.0.1.12-8000- 23542300x800000000000000040545Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:05.561{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F31954A4DB8DA64B5F39866F9DE821E3,SHA256=6084196B7C24C611D0997C60683A7E971A45CC80D2610183F73D6121C9B56871,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028375Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:05.158{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5A62A9EF69578CA146E3B455A9D652B7,SHA256=7B71C9332BEB61C836F3EF7994A4A8009F2A43C80A2179DAEB49F87D9606155D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040572Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-780A-616D-F208-000000000402}4916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040571Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040570Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040569Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040568Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040567Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040566Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040565Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040564Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040563Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040562Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-780A-616D-F208-000000000402}4916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040561Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.844{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-780A-616D-F208-000000000402}4916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040560Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.846{8D4DD44E-780A-616D-F208-000000000402}4916C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040559Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.577{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9BB0CF381D9FA11CC23905CFECE8174,SHA256=77A307D232CD4B41FE2B02C14A1A0C99E983FC560FF2F4D20B94FC361E2B2E8B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028376Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:06.173{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8CB0E91AADFC58EDE4F28D33DC4880A9,SHA256=78C894A074A4E0BD5CA9F81C56445F764EFB05AF1C00BAE168A3F60D5B2B3CDF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040558Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-780A-616D-F108-000000000402}1312C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040557Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040556Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040555Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040554Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040553Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040552Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040551Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040550Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040549Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040548Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-780A-616D-F108-000000000402}1312C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040547Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.296{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-780A-616D-F108-000000000402}1312C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040546Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:06.297{8D4DD44E-780A-616D-F108-000000000402}1312C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040590Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.687{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=20CB155FC55E05D198DE0BC6DC1557B3,SHA256=66580B8D6B2DE982895D768A9E1A1D0DE221652C91A5BD0C286DE44B40789905,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040589Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.609{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040588Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.609{8D4DD44E-780B-616D-F308-000000000402}9124964C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028377Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:07.174{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=01C05CC28F1EE87F72BCD89B0BCE5332,SHA256=FE698D39A393026D0A62929B285859F1EDCDB1F87A951EFBDBCE01C9F2F57D0C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040587Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-780B-616D-F308-000000000402}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040586Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040585Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040584Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040583Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040582Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040581Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040580Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040579Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040578Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040577Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-780B-616D-F308-000000000402}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040576Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-780B-616D-F308-000000000402}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040575Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.470{8D4DD44E-780B-616D-F308-000000000402}912C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040574Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.422{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=38033FB326FB008823CE7191B0E174CA,SHA256=AF821F151F85A370DD25648B8BDB4CE24C4823A683AC41383032F632E744C3FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040573Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.422{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0F69FF45BF19A0C56F457C39E2E49222,SHA256=A21434A2313BF40811DDF56374BA7A6C33EFFB5F86D3DAB13F5BC1F4487995D6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040606Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.687{8D4DD44E-780C-616D-F408-000000000402}20364988C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040605Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.625{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD818339A555E5748AFDC1B695787351,SHA256=59DA3292F8238F1ED4F76F779AC4F9C222F47807F0CBAC86A9EE1B28E5DDBDDC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028379Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:08.268{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028378Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:08.190{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DF145DB7BB0AD057874FED6EF0DE7FC,SHA256=C37ADA7CC3271A846AD9DA9444E43111BD1AD38D33548A1D54E63B689755EF7D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040604Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-780C-616D-F408-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040603Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=38033FB326FB008823CE7191B0E174CA,SHA256=AF821F151F85A370DD25648B8BDB4CE24C4823A683AC41383032F632E744C3FF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040602Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040601Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040600Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040599Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040598Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040597Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040596Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040595Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040594Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-780C-616D-F408-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040593Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040592Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.531{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-780C-616D-F408-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040591Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:08.532{8D4DD44E-780C-616D-F408-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000040637Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-780D-616D-F608-000000000402}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040636Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040635Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040634Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040633Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040632Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040631Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040630Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040629Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040628Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040627Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-780D-616D-F608-000000000402}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040626Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.969{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-780D-616D-F608-000000000402}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040625Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.970{8D4DD44E-780D-616D-F608-000000000402}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040624Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.719{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ECB6EE90C3CEDD41B036C53DC6174DF1,SHA256=45526E5EC98629B364EB7CBD23E7430A7F417C5D8B60111409FB5AFB85866FF0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028382Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:07.812{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51094-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000028381Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:07.610{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51093-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028380Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:09.206{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8DD93B3E44DAC2755F2CBEE75742015F,SHA256=2BFA4D4B9BF2DCD21DD18181BBD203E52D0E17D72AC5B91585EE9BF1818855DF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040623Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.547{8D4DD44E-780D-616D-F508-000000000402}45201932C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040622Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.547{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5A24C76792EE6E04BDED8AAA1B5F2D17,SHA256=BCBC3AF66DF25D5DBF2330B1874432565871B51699BE350BF8239AC3DEBA688A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040621Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-780D-616D-F508-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040620Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040619Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040618Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040617Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040616Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040615Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040614Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040613Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040612Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040611Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-780D-616D-F508-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040610Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.390{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-780D-616D-F508-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040609Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:09.391{8D4DD44E-780D-616D-F508-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000040608Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.469{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58944-false10.0.1.12-8089- 354300x800000000000000040607Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:07.030{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58943-false10.0.1.12-8000- 23542300x800000000000000040639Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:10.765{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B19060270D93C8000954B954CECB6E91,SHA256=A540B35FE5DAE87F72FC3D34DE40CCEEBFD6C2EB6751E67E987669BD81755F7F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028383Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:10.221{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6A9C7AC5D153A7C7971AD69D86DF74C0,SHA256=E088692CFFD6DBA2D46D7965AD4656CB4B777CD21A2C6E7253248E7AB441010E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040638Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:10.203{8D4DD44E-780D-616D-F608-000000000402}32204860C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040641Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:11.797{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDFA13BD8AE3EC6E8F5DAE959ACBBF0D,SHA256=5002BB19837A6F0E07BF6D123C0089A1FB16F9106E7014DDF219BB16C89C2EAF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028384Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:11.252{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2544B878F5EC8150387814B6BB7520DF,SHA256=F46014C2CDB6AFCEF132A0C2F8D939C69716E70755A22EF2911E4D63038943B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040640Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:11.172{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BF5C14F01E2F285236A004374DE41A81,SHA256=EF7823A31399CAC0AA973D400100B2D7C9B84EFF9A90D4D9489D5E1BB1D58BD7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040655Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.812{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BFCCC3F01A00FFAD1D795416CC710DE6,SHA256=5FE6FE59312F0C39644121F724CC82519EE7BDF0FC5B2A2DEEB4C3B3F86FF20D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028385Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:12.268{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0FEE4124B8E343397118434EADB033DC,SHA256=7B3FB6E6D960D088719C14F3962579FA70A5EBCC551BABCDDAD1E6B6C424AA5C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040654Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7810-616D-F708-000000000402}4244C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040653Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040652Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040651Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040650Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040649Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040648Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040647Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040646Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040645Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040644Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7810-616D-F708-000000000402}4244C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040643Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.078{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7810-616D-F708-000000000402}4244C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040642Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:12.079{8D4DD44E-7810-616D-F708-000000000402}4244C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028386Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:13.299{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=65132E5B41DA968A17C5D43D65DAC48D,SHA256=3BDBF35C1F0B7456D3F4E2A4881A6B591E98EDE371EF52B36AF75DAE674273F6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040656Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:13.109{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B069C4C448EAD719EAC7046B6FCED1C6,SHA256=3DD953C35DB0631FA9D5B26E0A8F32F0E734C33CEEB54EA86658883E39BB943D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028387Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:14.331{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FA02DEBFF1E69A7FFF3AB769DDDBD642,SHA256=B14BE7CB2AC4F22C7C9027F113CB92ED9C0719D7F08D9A76870550CBE093326E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040658Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:13.077{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58945-false10.0.1.12-8000- 23542300x800000000000000040657Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:14.047{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2EBCB3C9FCB04253B4AFA16CA2D71E72,SHA256=3D47B57CB36835D215295FEA2233863E45BE81317F5991270E879ACD4FCADC9D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040659Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:15.062{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE1612184BDF89B5EFA685797DFA0C63,SHA256=0C241AB7D0FCECCB12FF0EE956462DE2A92173A4C36BABD4511950C71EF8CBAA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028389Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:15.424{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F6DBB99DA8761F1E7CBFB817E994292D,SHA256=09E6C25EE91ADBD146A07EF0059ED09357C67E843C84A72F76440DC0A01E5EE1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028388Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:12.797{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51095-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000040660Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:16.297{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3C1B318CB1CD4A8DA36A12F552D260BE,SHA256=ABFD49C76E676313BABCA0208A30CE3B3699409E2213EF83DE30B63E67E86EE3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028390Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:16.456{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=77C876120013A63BE4BB6E32DB422A14,SHA256=DDCF0D0EAA2D7EE4D440EFE918158294C28FB03C985A0872EA5BE05A9B099BE6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028391Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:17.471{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=33DD96ECF0EC5D713154C9102A21D366,SHA256=CB6B417DFDDCA9B11EE0F1499C14D5CCA054D7F6F1F17A1215F78F9A0B0032F3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040661Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:17.328{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0DB181F13D9F9F42B223339EB5CE50E,SHA256=18FA2F2A42D275B0782C1B4B5FC4AB6C024614E37FEBCBBE8A055CA5396CD21F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028392Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:18.487{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=31AC8E965F8CBFAC64F1EB7BE26BC117,SHA256=43C58E0CA37756B802653D73EFFC569C95135EA4D4238E38F91C35B61AE9BABC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040662Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:18.344{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=46DC535A839F2A9AA965659A41FD24C6,SHA256=AF86D774C9CBA8F1EB81208BDE277A7983E85D0A94962AEE1142A754EF65E53B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040664Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:19.377{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76067CFFEDEA942A6D78956976234E19,SHA256=176E28D3BDC65848087C97ADF3213889C762CF4ADDF83FF9173354AADD2AB5B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028393Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:19.487{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64C36162B6E935CF9EC30A05C5F8F700,SHA256=310BF5DE65FF7F98AB18A147FBF4627259A605C4034885B1F39479C81E7220BE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040663Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:19.254{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-117MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040667Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:18.873{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58946-false10.0.1.12-8000- 23542300x800000000000000040666Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:20.392{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=558EBFF946565A3F9425E9CD9D69A302,SHA256=4BABA3AFEA9CB70F40FF080E64F04867B272E0413D472B149D8A2A318253A10B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028394Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:20.502{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5248F850F87B0E532B3D838632C03CD2,SHA256=3A5B8F930B72A52ABE51E111B9E8AA38ED7A3012BD3B8A18FCDAFD1DBA43A064,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040665Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:20.253{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-118MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040668Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:21.411{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC832599536F03BCC2ECEFFBD763E956,SHA256=DFD9ABD62BC98BAED1618A9527A4D0BAA527B03481335FE031AEE8532ECE2454,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028396Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:21.534{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E13B23D6197E8807B75AA18F66DF4FE,SHA256=F78F5F110845BBC8D48ADB7E30594F813B6387144CFA8811C19F568C15DF6572,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028395Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:18.703{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51096-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000040669Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:22.457{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C1C502931CB80EEF54881A193B9BF69,SHA256=C7BA63F402BFBEDE5A24276AC08366629B1B572A3BDB9515BBBA1270CE5571C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028397Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:22.549{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=871E3AB1CABF243274EEEB6F66C80B9B,SHA256=EEEBB1DCEBBBE29B939C85BBAD1995CC14A0E487A9C406DE095CF60356650266,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028398Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:23.565{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C333206BE9348878322D6DB5A0EC6736,SHA256=50BAF8357F042EF4CA72DB3BD21FEF2CA8C483C3A9AAA016367D97DC581A7BB7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040670Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:23.536{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8ED3E4D3154E42B2DCFFBECE8DF21E1C,SHA256=C74EB447BE877F8E065988A62AA958D783CE5D1117B28D0000A6A4B7FBA726DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040671Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:24.536{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE6FDB6E813630C3BAC7D4E62AD75730,SHA256=37229A61DCEB9AD7647D6A6E89B7FAF29A305B6C6627C200102DD479CBD5D38A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028399Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:24.581{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7AA55020005CD68702C46BE8F15AC4E,SHA256=9C49069EA3195414CF931273E515F345F9AD9DA211C84FCFB9DC952190460E30,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040672Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:25.598{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BE53824A4A64BA15FF30625313C1FCC4,SHA256=67F285401DD0DD25C9B0DF402F5BBC775DF70936519878F40B9CF8F93702FDF0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028400Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:25.643{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E0B59949AE58D4B5898C8C5F1663BD08,SHA256=A06ED6DBFD95275D7C6401BB4686C0E669EBE6138FC5036DC0765F04D36E7C2C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040674Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:26.676{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC0B0C28AACA3CCDA620D3C22FAB13A3,SHA256=596C4EC4631A02FAF4E3C06CB4E6F89D1E094DEA8D5A67DF1AA268924FBEDEE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028402Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:26.659{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDBE7A4A282D83B84B1E4626AECEBAFC,SHA256=D740F02F9E22849F590D5E8ADEF5419817995E4C7125368D7B95F44275A7D452,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040673Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:24.034{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58947-false10.0.1.12-8000- 354300x800000000000000028401Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:23.765{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51097-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000040675Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:27.770{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCCE9F8BE34C59944E57C6DF99CAC8F9,SHA256=832AD37C5515CDFD1E9930410841D1B20440BB4FF1EDF1A1F1B128BF769D21D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028403Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:27.695{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B4F5548150173B08F213ABC0AAEF5BCD,SHA256=153DC5E6D287E2E55552300D0B090ABD2661E0A01238FDC199BEBA5AADCE0364,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040676Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:28.786{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7973A197ACBC4C860CA1A3EE8BAB5717,SHA256=19A770AFA4BE5FE1E3EE2B6EF201F0876ACB26BDB4B9D1D5F04BA54AFD527DF7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028404Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:28.711{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E0C318534444AA95C61D33FEF794924,SHA256=25684ECF1E9B3B466D37EE5755D374B91C86C4B94EE1ACF4EFC44CAF166AC442,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040677Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:29.802{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=653B962C216B66B8F68C482C379C2642,SHA256=6A05F2654050A80269B58EBF8C7FF52B11B4B742B2B917BE6E959C4A681BC1FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028405Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:29.726{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE3309531BFFA0C8BDB8474B74101F80,SHA256=B0A56F6E6F2F70525613D2FF05D3CF0695C80766A6A9F467381D68600232C519,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040678Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:30.880{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=173494C9817FF4327291D4000AA8C31C,SHA256=49CAF5908F8D6B15B843C0D1B59355C9447B5B16C41D6451FFDC0CF2E84922FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028407Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:30.742{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C25EBD5946EF954C052898074D0757AC,SHA256=CA8D98FFD047FF715AC13E26EBC179B75598D01FBB256C5465F6C885B53D811C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028406Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:28.770{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51098-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000028434Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7823-616D-B806-000000000502}3144C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028433Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028432Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028431Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028430Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028429Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028428Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028427Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028426Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028425Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028424Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7823-616D-B806-000000000502}3144C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028423Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.929{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7823-616D-B806-000000000502}3144C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028422Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.930{6F8252D3-7823-616D-B806-000000000502}3144C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028421Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.773{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6CC3DCC36CD5719BA15912C3CA1ADE1C,SHA256=A599B79C58A2B1044907C6CCAE933D47B9B2EF0EA29CAB0F59B737CB19348F07,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028420Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7823-616D-B706-000000000502}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028419Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028418Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028417Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028416Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028415Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028414Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028413Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028412Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028411Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028410Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7823-616D-B706-000000000502}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028409Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.414{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7823-616D-B706-000000000502}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028408Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:31.415{6F8252D3-7823-616D-B706-000000000502}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028451Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.929{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FD2302CFDF15C4F20022E32352CABEC,SHA256=2B2E0B5394B180E7B12614B5C985C69D5D5329C33E2E6B0282317A770FB1DDEA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040680Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:29.988{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58948-false10.0.1.12-8000- 23542300x800000000000000040679Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:32.114{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E6D9DBC2F622F913C670E2A0C850E5BF,SHA256=8A91087F926DE8D76B67B654B90F860B632769B466DB3476FD0752C70C1C19B2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028450Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.695{6F8252D3-7824-616D-B906-000000000502}2752724C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028449Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2B9E5CB27A643CE52793A9CF986B583B,SHA256=C9D0DF34BEAF49E60B0C519E76C65D87C2775795582BB76B1968271B3B7082E0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028448Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7824-616D-B906-000000000502}2752C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028447Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A61C7A598D2F0548CDF301EB78E54024,SHA256=71781DB82E7E4F2C03E679A0EC9B09B84B1AB2E5C13B46950801A44D235F3CB8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028446Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028445Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028444Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028443Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028442Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028441Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028440Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028439Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028438Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028437Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7824-616D-B906-000000000502}2752C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028436Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.429{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7824-616D-B906-000000000502}2752C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028435Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:32.430{6F8252D3-7824-616D-B906-000000000502}2752C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028467Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.945{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6285B267A46CC7EC299662764F5589CC,SHA256=2302616F0E6BC20145C69C50D3515B72F07A92444BEC397F1C681E0242807A68,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040685Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:31.910{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58949-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000040684Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:31.910{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58949-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000040683Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:33.177{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4CF75E10F894BBC455232DFFEB4EC9F4,SHA256=3E4754275413698375A0BBA5D361AC2585C256B68E4147CC169E1B06BD778883,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028466Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.774{6F8252D3-7825-616D-BA06-000000000502}9921700C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028465Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7825-616D-BA06-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028464Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028463Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028462Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028461Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028460Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028459Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028458Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028457Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028456Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028455Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7825-616D-BA06-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028454Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.554{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7825-616D-BA06-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028453Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.555{6F8252D3-7825-616D-BA06-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028452Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:33.445{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2B9E5CB27A643CE52793A9CF986B583B,SHA256=C9D0DF34BEAF49E60B0C519E76C65D87C2775795582BB76B1968271B3B7082E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040682Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:33.052{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=78AED8D31E2A170C5ED9F13AD4EEEDC3,SHA256=DC05F70D64C6D616691A85B5482D9ECBDD99E849E79782DB546FA6E145CF00DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040681Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:33.052{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9767922DAAD739BF0D0E3CFAA4A565B6,SHA256=C8147B49541DB138EED0AA1B47C31AD39DB66CD6B018EB83A1779B4EFDE1D816,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028482Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.992{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=261B60C5555B13CB00A2FC8E2EC1B460,SHA256=FB7142269C98482226D3D064E14666DDC104BEA94B70947F7E0CD6849A3A7BA3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040686Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:34.208{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11C780C17471AFAEBB21DC14A8E7731A,SHA256=5841D57D61F06F86DE5F608A56FC56572CDC7CE0835CC2CC6AE2A92E4F580696,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028481Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7826-616D-BB06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028480Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028479Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028478Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028477Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028476Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028475Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028474Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028473Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028472Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028471Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-7826-616D-BB06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028470Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.773{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7826-616D-BB06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028469Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.774{6F8252D3-7826-616D-BB06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028468Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.570{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E886F24F4930778C415D4C77AC679529,SHA256=DAAF9A267CFD67D9125FDF27BA33B7DE2E0CF8D33837BED1F3D2DAF2E111BBBE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040687Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:35.239{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4B8DC7179A9315E87B6E4A86159CAED8,SHA256=7EC83A662E6214148FA7B258570528595F08654458BFD8F7D18953F93131C604,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028497Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.789{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D9D128C205B3F32CA3ECEAF7B37BAADF,SHA256=D68CB1FF179A9327EB145FCAC589125CC30079322C1367360F402BCF3746DC21,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028496Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.632{6F8252D3-7827-616D-BC06-000000000502}13164040C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028495Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7827-616D-BC06-000000000502}1316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028494Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028493Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028492Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028491Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028490Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028489Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028488Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028487Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028486Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028485Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7827-616D-BC06-000000000502}1316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028484Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.445{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7827-616D-BC06-000000000502}1316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028483Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.446{6F8252D3-7827-616D-BC06-000000000502}1316C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000028513Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:34.770{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51099-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000028512Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.320{6F8252D3-7828-616D-BD06-000000000502}2748328C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028511Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7828-616D-BD06-000000000502}2748C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028510Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028509Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028508Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028507Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028506Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028505Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028504Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028503Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028502Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028501Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7828-616D-BD06-000000000502}2748C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028500Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.117{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7828-616D-BD06-000000000502}2748C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028499Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:36.118{6F8252D3-7828-616D-BD06-000000000502}2748C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028498Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:35.992{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B48BC8A0F96CE805D08031E3CC91752E,SHA256=3E8C5EBD2F525FFBEF46122383AF988521F4F671767F6723A8C4AAB84BAB25AE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040689Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:35.003{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58950-false10.0.1.12-8000- 23542300x800000000000000040688Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:36.239{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16605B59BB9E1B76C4787CE25E505356,SHA256=EE4209AF4C9B55C31FD43976FB8ECB712ECA1D5D920297BA5FD90FF49C1882B7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028515Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:37.148{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4C8596DF254157F5DF170BFF1BD91DE0,SHA256=FC215A0761E23F1AF1B26730E946907FC620FB7EA0BF7A7F5653EAA75A53AB08,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028514Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:37.007{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=436D23DC1521C11C3CD043B85083EEC9,SHA256=85802DB72EB21DD5954927F04C0C366B147C4879857284F3033245EB71825B20,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040690Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:37.255{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=29E46046C4F2D29485253E74B8D99970,SHA256=A754BD970914624DD18873D7E72F2210AA22D6CAC79D80D3D8870251AE490F6D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040691Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:38.286{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD168063D7B81F331198EC17F1851DE7,SHA256=DE71DDBF4B853C058FCF8C21887C8BF353C6E4426E96754AC0A765EDB05A3459,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028516Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:38.039{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B088956DC754E4DA99F77DBF62B71796,SHA256=E06E70CD322B8AC9A4BCDC3CE12C54299155D95A2C9F1488415FD2DDED9D191A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040692Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:39.302{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39385D4A7C7660BD7C7016F8BC3B1185,SHA256=1CC7F5262B11A5FAD24E3843833A26EFC609DE2003700C6E0DE778D40F41CCA6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028517Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:39.054{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E1BFD10749775E4EC10733CB7DAE832C,SHA256=8ADBADED87502EFDA632CBC1B509BB180980259EC7638861E704D94F39AEBF05,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040693Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:40.333{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=17C4523FAD7850FF4733FE507BB61691,SHA256=295B357CBA505F44B2FED422E2B8642145DAA70B0706E81530F28DF3627C7519,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028519Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:40.950{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-109MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028518Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:40.070{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D167A0C61DEADB02F9E4892F5471D23,SHA256=DDF58F612D9D56FC44AC3782E521B2FF102A2E9647287CCD882A8618946E2FE8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040695Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:40.066{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58951-false10.0.1.12-8000- 23542300x800000000000000040694Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:41.349{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEC3FA67CB698FE5BC0895D5778B67C2,SHA256=0670AEB4A51432FABAA4873584042A27AC9EC253CE30E0F2C27A2A9E48CA856B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028521Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:41.948{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-110MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028520Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:41.073{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=313A856AC4F67A95880ECE3F02E98E72,SHA256=8617308159C94A10B19C0325DB6566FA49FEC38084CC334A12A3A19EBCCE63E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040698Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:42.692{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=726585AA579E530FD8E554D321A9F484,SHA256=2038C46AD8AD416082EF3B060EA02875D22A87C9A8830D7CE33DC575ED3553CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040697Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:42.692{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=78AED8D31E2A170C5ED9F13AD4EEEDC3,SHA256=DC05F70D64C6D616691A85B5482D9ECBDD99E849E79782DB546FA6E145CF00DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040696Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:42.567{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0F3CE6C34891FAA24489A0653FEEC7F9,SHA256=2BD05077EED3C931B9A44B948B3FD725FF92977A4DC3D7B733FB9883E0AF0840,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028523Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:40.601{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51100-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028522Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:42.087{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9971C88C7C23EE908D40322951ACA30,SHA256=9A38C05E0930C500213DC7D281F9B502094F9774B7E4D6D307388604F88F76FB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040699Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:43.801{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A3BC1B558EBB2DEA21F37345BB7D0B97,SHA256=22B5C151EAACA213890FE2B15D25E991DF7ED5B1CCECD7741953DB80B886584A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028524Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:43.089{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7FB139D7D14486285948E91CE5EC7D49,SHA256=335E992115A86768FF38625DB2251F81E356B344E3BF3CBB8D727A1642A14ACB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028525Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:44.105{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C04C329C40EC9E08765884D001C4E276,SHA256=20EDDD2033447C74A2068EA6FA7A792D1E4EFE90C93C0A5FF7E95991C1FF7A73,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028526Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:45.105{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C62A3C02965CBBFDC761B493FF48CBB0,SHA256=5007D31FA8509406928F085A96A967C0D4394179BE46B7E05ED49C49BB097416,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040700Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:45.005{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D90173415E7D14A85E803DD3331CA476,SHA256=EE3EB73FBC16A44CA59E96EDA4D55447F992E0871E0C25DBF828BA858448B6A4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040701Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:46.020{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=89C3C13B4D32EE8E8BDF7B4DF9BE75C0,SHA256=27B657662F15C3740F283B316B5CFC9D7E769163A7D4CF638EB556FD407A397A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028527Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:46.120{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A40F0F3D48FED5D979E19C48A58F93DD,SHA256=764A85E60FA0D56C8AB58C8BAA3B65601ACD7E9A153DE9B37E60390F7FE44821,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028528Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:47.132{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C0E18D19EFC9174C51232FE0B69B0F8,SHA256=9C2DCE221A412474E5A31E6F5ABF5435E0A4050F01B08DA8FA8849B030E2DDE6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040703Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:45.925{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58952-false10.0.1.12-8000- 23542300x800000000000000040702Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:47.035{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24EB24368F4A5894516ED3139D11BB35,SHA256=3EB2367FA1C6722ABBB537C43FC17FB1AE9E383EDC44B9D8AE62A4D5523C1026,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028530Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:48.148{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5B160998D972270500C68B6B926332A,SHA256=37637BD0AF937D447EF9BA2E4BA8CFCBBFDFB608C8F16EDBD979FFB26592C523,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040704Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:48.051{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=280A11EB3FB243E4E401D567B5198749,SHA256=4BE44203FB1CEF9446650EA88A3DCE688A14BE64906D66DDBF26E14CAFE95AB2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028529Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:45.773{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51101-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028531Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:49.165{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09912CEEF0545A401AE9329EB4A04A63,SHA256=AAD56252D77D0225FC5320E6552F860713CE21437F084483B7F7C18898C47296,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040705Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:49.067{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06028C728FD931850C4D3D87BD258321,SHA256=8BB8C0ECAD46F4FC9D55097E9F25B5BBF6A1CAA3F4742B4DDA1FD13AE6B77529,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040706Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:50.082{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8629B02D8C8E635287121059C341392F,SHA256=D802489869C751D55C10D206C03CF326ADFE83F8069ABF9647EF080C6E4F77DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028532Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:50.180{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E57485397840B261332347E09E88216C,SHA256=922242EC292B3D5DA3360654BAF0F5F9FB0C9E1E4BEAB9BF860D3D55D7558A5B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028534Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:51.790{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=2DBE0374B26E4520984C588A759BA8AC,SHA256=92A2EC70DADFD2531227867B734BD75708671063E4211EF0499AE2907FF0C079,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028533Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:51.196{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B96182B98F6B04F030183FFD2363D6A,SHA256=F3D6FB9568A32E44A623A11CD95610832CE1396738F1BC9F4F4D91546E87E998,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040707Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:51.098{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=004985BACF4612FE5EB721734F7A2E56,SHA256=AB96FDA8938B41F4F9508488137C643931715F45CB5EA2B58152D31BC695FB33,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028535Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:52.227{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7ABD758BEBC448F15C322E3A22729393,SHA256=E3046A6CCBF7D384ED27A7577D44AC152AA9043AC4C6B0AE1EC7F3E4EBC8EF8C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040708Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:52.114{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F37E3A0DFB6CB90D46DB528C1452DBD2,SHA256=44E9610841CB80687405DBC5BBFCBB7DEE16AB2DABDEF9A360A23D2A6D7F9ED6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028537Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:51.644{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51102-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028536Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:53.258{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F23CB3DBD3C97CB317996C6B07DD9D36,SHA256=239AF3DE4161F904EF295BC626D145E733C753E88431B6319EB2C0C1B3CCDF7E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040709Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:53.129{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F281F972B3D73EE12CC0B5BABFEFFC1,SHA256=B4066CF74A3318392B71016CF1A7E098E21D071C5E1A00B6B981DE82C5D13D7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028538Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:54.274{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=80CF1B664C28A109671DCC87FEE03D8B,SHA256=694F6FD0629B14D104DFB689876384CC9B5D07A7D4E1A4CEA92B97EF5D410FF2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040715Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:54.160{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA5CDF946ED26625BEFA6F7B4F3A61D7,SHA256=E6F7B1D37B3891928C9F222829B36D00ADF893869A709387379DBF939A994DB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040714Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:54.129{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4054AA2B09E3CB47DCF89D77A1695097,SHA256=376F47B602A841AF6BFD9FCFC427DB270B932EA745B395401BD51293DA2664D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040713Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:54.129{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=8C7B3BF0150F777CC244FF5BA03E7300,SHA256=98DE8C70FEA7D627A9CF0647581AE3C5BB3B6C7842DDAC1048405DDC6C93ED8D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040712Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:54.129{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=726585AA579E530FD8E554D321A9F484,SHA256=2038C46AD8AD416082EF3B060EA02875D22A87C9A8830D7CE33DC575ED3553CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040711Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:54.129{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=DE35EA9C58C818A77D6A5815BDB55871,SHA256=7B2E5DA595409920D6D939515F1171B8EAF84BA1E7F8472F72AF428808E3D6AB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040710Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:51.909{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58953-false10.0.1.12-8000- 23542300x800000000000000040716Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:55.176{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=92FBC57C8BC68CE1ED752D2B3B596D1E,SHA256=C264DA7E8FB7DB9EEC28898A7818194955CBFFE8C7C66D97BD84345E832FF624,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028539Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:55.290{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11EFCE7D920CFBB91FB493841B40CB83,SHA256=A42DF885D751EB6BCE2F2E895BDD2160B35DEAFA71FFDBE580A1FB7EF44AD4CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040717Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:56.410{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=475E964DE5FBA0984659D0F6432D421F,SHA256=32080D0DF7E1FF18C04BD8B58551313A137CF81A7981CD8A147D5CF96B0E4D10,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028540Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:56.305{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=144A797275388EECE1282E06442F8D7B,SHA256=00DCB5487BCE5B60CF1BEAE01C1D90DE7E48AB285D1D6268242797FE5482F052,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028541Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:57.321{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F386B2863D018C6D83648FCD6DE6BBBA,SHA256=00C990AF186CB6382D8E4E901F31A93E89CAF617E5ADE6564B292E416A86BEC9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040718Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:57.426{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1EEECBE61AE3B6A782C16C3CF7B2F3F0,SHA256=DF8312893129A6DB3FAD8A2EB312EFB33FC380F1C8D2EC6CBC04B55D367A027F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028542Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:58.337{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4DFFBCEE2B7ECFAB03E23E73EB55E1BC,SHA256=097A057DBD6ABAD55C3042AAE9745B85FE5F3927CB10A79AC1E5E171E5547CB6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040719Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:58.457{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FDC7E566301B69258C8AD55DB48DD924,SHA256=B1EAC981A3F4939276EA3EAFFC5883C0B997CA099BCEFFBD6B8F02C6EBB2A0FE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040721Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:59.457{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85A0877F871B5B2FF479D94B231FBF79,SHA256=1FA44BAF26FCEC8403107B12A5B5B6418C99C56DCC32849F2F675AD77AFC771D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028544Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:57.644{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51103-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028543Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:35:59.383{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E1DE8F2554050C6AAEB1FC5F59EE5032,SHA256=322D314D3DAE11DDF83470C7EA0483F0CFFEC3E648BA72E9FC9BDB6F4893A033,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040720Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:35:57.003{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58954-false10.0.1.12-8000- 23542300x800000000000000040722Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:00.488{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CDF168B1A27C4F82F0130455DB11FDD9,SHA256=B1A0F74CA9F17A8CEFFC94FB3FE92EEC7D5C38AEBAFACCFAD20E069647DD76F3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028545Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:00.399{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=694689F3F90B89E2FD05DBB527967A90,SHA256=6D51528067B8D600034B9E55A3133FCB7A536BFCD1EC75068DA7CAE6C9A57C93,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040723Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:01.520{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6D16DA5FB8F996BE1FBA23C3627CB8F6,SHA256=13C0FF6C1FEB0AA686FE8A16768E7CCBB51AFE8E13E9E37BF67D82E911CEC414,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028546Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:01.415{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0533DCFC96996F0125E89654A59AE30B,SHA256=7A22A0A0A7394172690420183158781A689D0079E3CBD6FD70736161901087EC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040725Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:02.754{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=45FD20F5DCAA546A4D194B95F1F5564B,SHA256=C5D75486E37DDA31935B14A4A329BEFC74E08FAD20F5AF9770F56ABDC1DDFDBF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028547Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:02.446{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD58E5F95481C82CFBEAB12BCDACB207,SHA256=846F07DFC11530B495853EF62BACAB8C19229CA775F20B6807EC6D5887B0CE89,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040724Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:02.676{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=672EE76BEAA105A00B74D3D0A9A66BD9,SHA256=2D74EE8E2332D4AE1B76AA86D485E9B6635EB596B3EAEA5B7ECBA87F779035DB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040726Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:03.785{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=305BE6BEB8AF81CD1FAE61202DC94FBE,SHA256=914DEB665924FBC7B7991F86CEC799EC9ACAA3696FCD9EC08746E1A708CC6994,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028548Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:03.493{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=73F222B61B8F74EED40CEC29EFF6352C,SHA256=4893F0E69F38018F29B52A23FDB3D72020F4F1A5C8E4BEBA28253C959C6285F8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028549Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:04.508{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1FDE711EB895036E028BF0691156BCFB,SHA256=2C45FF4E01FDCD0AA18459C05074ED774C6ABA3DFDF6E25CFA386B6BD29CA8C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028551Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:05.540{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A200C3C5079D0E90CB926C65BFFC82E7,SHA256=B5F01CE8335AD01902ED38CF65F811CDA67E8F5CB81AA492ECE846A23C23312B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040728Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:03.051{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58955-false10.0.1.12-8000- 23542300x800000000000000040727Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:05.004{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32E09995B2604F7E4372B3153FEB828D,SHA256=7103FFFA03AAB4F950AD03B327969D53194E51DE8C6EA6848C28870EC120B72D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028550Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:02.784{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51104-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000028553Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:05.290{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse80.66.76.146-63813-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000028552Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:06.571{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DA12F455D33998E98710C6B3A88E1C4,SHA256=2B3C19740E5212DD9294E4AE4F01C1AA0AE692577240330D71EABFE4557E6113,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040756Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7846-616D-F908-000000000402}1060C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040755Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040754Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040753Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040752Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040751Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040750Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040749Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040748Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040747Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040746Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7846-616D-F908-000000000402}1060C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040745Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.972{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7846-616D-F908-000000000402}1060C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040744Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.973{8D4DD44E-7846-616D-F908-000000000402}1060C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000040743Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.504{8D4DD44E-7846-616D-F808-000000000402}45642404C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040742Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7846-616D-F808-000000000402}4564C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040741Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040740Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040739Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040738Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040737Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040736Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040735Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040734Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040733Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7846-616D-F808-000000000402}4564C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040732Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040731Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.301{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7846-616D-F808-000000000402}4564C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040730Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.302{8D4DD44E-7846-616D-F808-000000000402}4564C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040729Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.020{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C5F5AB981E002658C3BD865533602E75,SHA256=701394EE7A7E833B9B18167049672C041903A5FA26C6B1D4F0D4D1B04B4EC598,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028554Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:07.617{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B17F035A33421AF422809A3FDED5AB65,SHA256=01030AE14BB95017686DD7B85DFDEE45E9355D0C7BDF94B7C59F45D2CF5FE43F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040773Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.644{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040772Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7847-616D-FA08-000000000402}4772C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040771Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040770Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040769Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040768Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040767Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040766Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040765Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040764Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040763Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040762Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7847-616D-FA08-000000000402}4772C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040761Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.628{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7847-616D-FA08-000000000402}4772C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040760Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.629{8D4DD44E-7847-616D-FA08-000000000402}4772C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040759Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.316{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7C7346C532E2C91E784DACB5C99D3409,SHA256=35501AF27C7455E65EE194B6D36B8D00A3D878ED829D9D5CF23BBD3BD8C92DFC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040758Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.316{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4054AA2B09E3CB47DCF89D77A1695097,SHA256=376F47B602A841AF6BFD9FCFC427DB270B932EA745B395401BD51293DA2664D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040757Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.160{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2C682B92924231418403B1448EB1CA5,SHA256=AF126B18C7A3FF9D67682674769B5A75C1EBB77E340A0853B75CE2F286A45DF4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040789Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.691{8D4DD44E-7848-616D-FB08-000000000402}32402192C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040788Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.628{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7C7346C532E2C91E784DACB5C99D3409,SHA256=35501AF27C7455E65EE194B6D36B8D00A3D878ED829D9D5CF23BBD3BD8C92DFC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040787Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7848-616D-FB08-000000000402}3240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040786Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040785Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040784Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040783Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040782Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040781Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040780Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040779Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7848-616D-FB08-000000000402}3240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040778Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040777Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7848-616D-FB08-000000000402}3240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040776Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.519{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040775Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.520{8D4DD44E-7848-616D-FB08-000000000402}3240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040774Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:08.331{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0255BEF3290BB887D2EA577940A7B82,SHA256=F7DB3C3E96646C6680642B67D401FA6E212B4653B589BC9C3591CAEBA88E74A8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028556Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:08.633{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BEBF916147CD54F320A53162656FABE8,SHA256=FEBBE9ACB909E97AF37D66194ABCD8739CEC5168EA5C6A8DF693122C48D2CC6C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028555Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:08.289{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028557Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:09.648{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BAD3691F4B8BF9A6ED3B290A7B5D0F34,SHA256=1E0F3921B7FAE2B030D1C0C6ACECEF6FDF258A1DE53959D21F4D7EFA80A9FF0B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040806Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:07.502{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58956-false10.0.1.12-8089- 354300x800000000000000040805Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:06.736{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-185.attackrange.local53domainfalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal51829- 10341000x800000000000000040804Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.566{8D4DD44E-7849-616D-FC08-000000000402}15642168C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040803Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7849-616D-FC08-000000000402}1564C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040802Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040801Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040800Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040799Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040798Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040797Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040796Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040795Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040794Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040793Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7849-616D-FC08-000000000402}1564C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040792Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.409{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7849-616D-FC08-000000000402}1564C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040791Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.410{8D4DD44E-7849-616D-FC08-000000000402}1564C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040790Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.347{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3B297602E981436F3EBFF4E9760F9821,SHA256=C9ECA56855471DB38F3EC7BA3CA957A487445F231BEA4E3ACB9779B1C27CA2E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028559Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:10.680{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC525A686596ED4C31DEC0B19F2968B2,SHA256=37670B3ED456C05D94C954C37FC34CFC08E51EE1EE68D9EA0B65F72BFD68F5A6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040823Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:09.033{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58957-false10.0.1.12-8000- 23542300x800000000000000040822Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.441{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F6CF87B8695233D1A1508274B82D19EB,SHA256=8BFBBB8619ED43232A4F3A835DBBFFFE11F51BF5FD0D6DDD3B892CA6CB969114,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040821Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.441{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09BEE5CAE347E1FC1A89937F7B97B881,SHA256=06C72CCAB483ECC68BA8C3671466F2CEEA0139872D9A9984C80F882AA14CBAF0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028558Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:07.830{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51105-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 10341000x800000000000000040820Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.253{8D4DD44E-784A-616D-FD08-000000000402}19005044C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040819Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-784A-616D-FD08-000000000402}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040818Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040817Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040816Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040815Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040814Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040813Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040812Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040811Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040810Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040809Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-784A-616D-FD08-000000000402}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040808Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.081{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-784A-616D-FD08-000000000402}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040807Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:10.082{8D4DD44E-784A-616D-FD08-000000000402}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028561Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:11.695{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1491E185C23AD260063C32C5D5A4DCF,SHA256=3F3557B832709D2616E7D052309F195109B3BBC4452F51F9F07EC0BD6898F9B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040824Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:11.550{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A0F9FAB4F4C57B1F87902DBAECB46E5,SHA256=9BA1EA0412DD5E23CD27B31F99700DC80C506C0C8AB1A1228120046B6E82D50D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028560Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:08.815{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51106-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028562Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:12.726{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1A27947598696673A5EE6DF8D4FE3841,SHA256=5D80EE5ABB30895A89F5696C88D1BAA2ED7EC4CFEFAA6F4EEB853F70DEFF0738,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040838Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.597{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=653A786B289BF67E0190F66EB91C21BE,SHA256=DEAB8B5941F10F3FEFF78B912EA6A4572AFC2EA790C2538C045BB5AC41560D73,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040837Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-784C-616D-FE08-000000000402}2448C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040836Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040835Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040834Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040833Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040832Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040831Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040830Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040829Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040828Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040827Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-784C-616D-FE08-000000000402}2448C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040826Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.081{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-784C-616D-FE08-000000000402}2448C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040825Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:12.082{8D4DD44E-784C-616D-FE08-000000000402}2448C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028563Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:13.742{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=409631529FB0579AD5EB59506B4C201B,SHA256=41F537D7367FCAFBDE0707517D9585CCD0345B5B76B432482565F95DF6944E7E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040840Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:13.644{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A05ECBC139377C9AA64E4E6F55C99D1D,SHA256=246D96614E8F62254E1C16AD931F830504396D1230A6CDAFB42ABA2BC2594199,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040839Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:13.097{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=75B9DA8AF52FAE9D930E71C609974AD1,SHA256=51F83EDB693645DA7EB17E1BF973AA5D574F2C8E5C610571D8D5C9B72CE21A02,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028564Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:14.773{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=059879DF4AD65DD7B22247B90FA8552B,SHA256=4595763C0EB52AD4EE255B1462AEC3F02B77BCC7FB2F792295ECA753009B65E5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040841Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:14.722{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC44823B579A98D7D5B7CAE3E51F5868,SHA256=08CC08B2086E71CB696AF4F8886EA111DACC754FCE392FD9C0EF608543D7719B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040842Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:15.941{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C96510B6D283A3E9BFD34E32DB90AF1,SHA256=41CC93455785D2B82BC16C8B63E96191328ABEEE3C525D8A5965F5BEC7A7C457,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028565Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:15.789{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7631F2A974FF4155A53580B1771E09FA,SHA256=AE86B42F5C903C6B2010D63B351FAAF62D9BD39A0DBD4AC9FBABEAF0F9E09A13,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028566Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:16.804{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB396EF1E2D90EB12773ED6467A0ECAA,SHA256=291CE2A169E0C1AC98703DC7CF2468B9B231EA1C3859C08D567685DA07A10663,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040843Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:14.080{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58958-false10.0.1.12-8000- 23542300x800000000000000028568Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:17.820{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A25164D4A125139B6870ACEBA830C53,SHA256=0189A22DABE64BF5013DC390BF3E72D2962CB17C2AA06CBC2638B71E633466AF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040844Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:17.175{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=167FC63C0A4061ABA208CFB0F422D1E3,SHA256=2AE72E21C9E9152CEFA91DAF09B62B6DF1CC6F67FD8EBAA41C1C55F86E0C9AF2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028567Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:14.752{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51107-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028569Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:18.867{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB3A0B129125966AA7AF929EA57DDDBF,SHA256=4EE32E4FD76EBE7399858EE4531F5D8DC1C054BC4C8B83D01119A6F859C73C82,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040845Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:18.409{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2CD68A974779192266114892823B2657,SHA256=75228A41B12DC2761AB611A7E06E0335C2D746C646BC25F318E37AEF1F5E4F6E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028570Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:19.883{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=685BCCF6EB74000868FD8CD420F050A0,SHA256=09720EEB4DBD19CC9FD92599A3CC918F1CFF47D480F4B51C141028B283FB2080,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040846Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:19.488{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CE80E18C7C178F84F32FE1614C377326,SHA256=28003210978EAE358FC7FD8D321FE0B4948B3C1A2C061C2B5DCC1274BB341FB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028571Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:20.914{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=515AE0DC51B84298E3F037D2DA052EE8,SHA256=4F0497BCC36D4A90612039F272254B461A5B0F561DD4BD94795E1AD221883A19,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040848Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:20.772{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-118MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040847Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:20.489{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9509F91CBA2BA23792269D576047E07,SHA256=AA98BA2D902EC3A71C27DA8186EAE476E97814A0F413D9774DE59AD6B744BEB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028572Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:21.945{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A3D5A27682E186380C7DA612F15BDABA,SHA256=1FB7FD56B980E7BFCB05CC755B5BD12BB8465F9430218F9E52CE832D2D7883E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040850Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:21.785{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-119MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040849Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:21.503{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4684ED17F659321978516EF42779986,SHA256=3CF0663A581B2FA9C6B09D67C704A9EF98248A48C3177C6786A83C497EE808E8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028574Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:22.976{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=010224F4059147E407D177CFB580A932,SHA256=6FF8EB760D5AA87E9AC2257E0C9ABA9C8F2A8A1CE6735053E1CEDD308CF0886B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040852Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:22.505{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C55E9A17048330D33044B4808750BD59,SHA256=05B41F191F37226F04551A07E514FE4F6A9D0C02C7107008C5718FB3D3DC715E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028573Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:20.752{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51108-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000040851Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:20.111{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58959-false10.0.1.12-8000- 23542300x800000000000000028575Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:23.992{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AFCA4EEF86E480DAF666D60420F22DC8,SHA256=35EF31391515478E7600E558160453E2A0E712A2B19551C585EFB26B352C3139,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040853Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:23.520{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B132D870218228D21C2087789D5FDD0,SHA256=029337B8FCB2420C7C5C431201CE8B93400B4B1D820ACFFE1E3FB53AA150A5D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040854Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:24.520{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B24C59E03BB9503FA06521686BCBDF39,SHA256=05A114C36B7FA4AF6F9AA6A4014DFFAF72774CDE046AF1D8191316B30EE45BF5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040855Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:25.536{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F60BD6BF5E1FCA854B7B5A9BF5749AEA,SHA256=C7C787313685832E008BBFD6A43BC356B33B72385F510FA2FAB60C18DFF8470F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028576Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:25.008{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E8A28B83865139A5C6AA46F2E7D90163,SHA256=22217894CC3EA93C219DE6380AF09C25E6446B4F55573448DEF1D509122F2D42,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040856Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:26.551{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD0D415067D17744FAF932F52FE9A6FC,SHA256=448DD3870C3870F39D7661ED7805424B01B4E5F06E9D3EFC2E46C05F2041DD3F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028577Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:26.070{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E33A3895DB1DC0228B363B765ED28F5D,SHA256=FD5A186A1FF3468D0F6797DBAA9994EE622063C3898D6E2C1C8046B669CA2623,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040857Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:27.552{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F4F4346E88BBABB49DACF1386C3B3848,SHA256=CDD530461CA4A7D978BAD184DBEBC98B8D175E657275FA37E427B9B5EB5DEB01,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028578Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:27.103{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=35825E8DA851020CC6231F1CD1393A0E,SHA256=038D51870A28EB23F06BBBC792393FBFBE70359B067E0595855EEB77202787B7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040859Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:28.708{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A961DC70449D0BA0A8AFD09945A3FB3,SHA256=73F65BB182E3F689E5EEC813BCFEFCC7EBF437FFDD1A6DEE9554A14F472F980E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028580Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:26.753{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51109-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028579Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:28.134{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B607AE9C2AD88F3804FE94CCEA0E7C7,SHA256=F66F628774BC189C4B2BC94302DFF4F4464FD60886F607DF7518B88EC82B5065,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040858Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:26.081{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58960-false10.0.1.12-8000- 23542300x800000000000000040860Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:29.740{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8739E3101B687B31818C2352BEA356AC,SHA256=C398C979D44DFA3A11A30D316A965DA288E9A4A4BABFE5762B19B6FBE9FBF1B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028581Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:29.197{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC21ED03552C7313F0C5E47BB32D3E58,SHA256=918739D6ADEB54EEE74B2154E77FEEE2D8CBBBC5BE9AB98EBB8289A7A560A7BC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040861Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:30.771{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F18023360BF7B2E7462E648286B79012,SHA256=C95E4980254D1C26280CE0D193136B6D5D5DD81E04FF25F4680D59CC41B7A97E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028582Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:30.228{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6E1154AA5143A812416D4D8E16ED453A,SHA256=A0C5EEFD1D4F8E0AFE5D8BDC95C91702462AF9F197A1AB0438BE9EF5B6795C0F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040862Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:31.833{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3A386F7285D20A96BBC53DF6CD9AFB9F,SHA256=484FD153841A764712492966780D3A5BD6F526C516235418AA446CA763DF8B08,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028596Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-785F-616D-BE06-000000000502}1236C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028595Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028594Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028593Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028592Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028591Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028590Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028589Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028588Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028587Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028586Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-785F-616D-BE06-000000000502}1236C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028585Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-785F-616D-BE06-000000000502}1236C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028584Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.416{6F8252D3-785F-616D-BE06-000000000502}1236C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028583Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.259{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A946040FB45D1043081331CA2F261B3A,SHA256=C5C3BC97478D819BAA5B25AEFDD8D04478795115E0E94C63A6D72C8830E7B096,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040863Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:32.849{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B5896886551AE4B808D737F5E8194D6,SHA256=DA9819C80F36C5AA28F542D92898F6E312BF1D801EEAB14EB66595573BC11C4F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028626Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7860-616D-C006-000000000502}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028625Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028624Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028623Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028622Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028621Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028620Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028619Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028618Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028617Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028616Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-7860-616D-C006-000000000502}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028615Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7860-616D-C006-000000000502}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028614Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=735483E972F7E94F3926C274F60A2A46,SHA256=865532F8CE95817E80D2B4B160B42B31288B8A9F014A730F8C20D1F66C62BC6E,IMPHASH=00000000000000000000000000000000falsetrue 154100x800000000000000028613Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.731{6F8252D3-7860-616D-C006-000000000502}3220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028612Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FBE4A8BC86672DCDD721BFED7A58EE1,SHA256=5C0B43B17D2D9F55EE0606EAA65C8DF5EA8B19193B31FA87141E41A0C60AAC5C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028611Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.728{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=823F421797853196D707048C7B8B7862,SHA256=129ABBFE781C451249B0BA189D1FD3E74C25E602D791A36FC11E350CD4912192,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028610Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.322{6F8252D3-7860-616D-BF06-000000000502}3544980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028609Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7860-616D-BF06-000000000502}3544C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028608Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028607Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028606Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028605Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028604Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028603Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028602Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028601Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028600Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028599Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7860-616D-BF06-000000000502}3544C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028598Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7860-616D-BF06-000000000502}3544C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028597Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:32.088{6F8252D3-7860-616D-BF06-000000000502}3544C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028642Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.791{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=735483E972F7E94F3926C274F60A2A46,SHA256=865532F8CE95817E80D2B4B160B42B31288B8A9F014A730F8C20D1F66C62BC6E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028641Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.728{6F8252D3-7861-616D-C106-000000000502}32003216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028640Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7861-616D-C106-000000000502}3200C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028639Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028638Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028637Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028636Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028635Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028634Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028633Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028632Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028631Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028630Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7861-616D-C106-000000000502}3200C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028629Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.556{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7861-616D-C106-000000000502}3200C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028628Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.557{6F8252D3-7861-616D-C106-000000000502}3200C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028627Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:33.338{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBDB2A1C278793AAF6C53AB9127B94F2,SHA256=A5EEE5981E54BC2851AC22402223A8DDFF34654A6DE9223E4D47B7357742AE31,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040867Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:31.926{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58961-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000040866Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:31.926{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58961-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000040865Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:33.068{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2088C4CCDF708425002F972B9EC12E66,SHA256=2D48E6BCC6FAD8A0C8E95D9F3E7B5AC939703048A0795626778F0F62985E2324,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040864Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:33.068{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9262154F869797F6554EB096493E86BC,SHA256=80FF849FDBC1E9CDD450F7DB92FFB258B6D43964FAC87B1E85D552E1E5C15C62,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028657Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7862-616D-C206-000000000502}3636C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028656Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028655Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028654Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028653Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028652Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028651Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028650Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028649Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028648Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028647Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7862-616D-C206-000000000502}3636C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028646Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.775{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7862-616D-C206-000000000502}3636C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028645Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.776{6F8252D3-7862-616D-C206-000000000502}3636C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028644Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:34.369{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=65561CAEC73D942D0116ED59E9E94307,SHA256=9A01B0AFBEDC07470F9E0A1274E2DF1DC7AC4FBE9C646AD495EE2895627999F3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040869Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:32.004{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58962-false10.0.1.12-8000- 23542300x800000000000000040868Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:34.083{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5CBC69A80A932BE6F2F7B13464911F9A,SHA256=11A57777946B057CA3183FADAD1FD7BE13A5FBE1CFE5E5B6B002B0BEF6A79205,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028643Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:31.769{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51110-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000028686Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7863-616D-C406-000000000502}1852C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028685Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028684Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028683Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028682Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028681Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028680Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028679Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028678Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028677Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028676Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7863-616D-C406-000000000502}1852C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028675Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7863-616D-C406-000000000502}1852C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028674Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.838{6F8252D3-7863-616D-C406-000000000502}1852C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028673Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.806{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F72206450F94CB676824FE4DD8EBCA09,SHA256=1889469B68983416694057D85A0E412912FD445C8B2EC681408A2A1A55B6A889,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028672Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.744{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A51A46527574C57CADC95049931B22F3,SHA256=D438555B775EB8294ED5DFCE67D83AC90C15285438ADBDE6D81840AD7AC84769,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040870Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:35.099{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1DA9116B64715DE70B2B83F2837555E8,SHA256=B7AB05CCBBE2128C9159A497884340D313D9CAFAABFB40779680441D14AA6A02,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028671Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7863-616D-C306-000000000502}3064C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028670Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028669Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028668Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028667Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028666Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028665Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028664Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028663Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028662Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028661Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7863-616D-C306-000000000502}3064C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028660Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.275{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7863-616D-C306-000000000502}3064C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028659Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.276{6F8252D3-7863-616D-C306-000000000502}3064C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000028658Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:35.025{6F8252D3-7862-616D-C206-000000000502}36361052C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028689Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:36.900{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B04DC7261D346BF30B6616F2952B1483,SHA256=E13A5683E0215C9BA24DA2BBF0B767EA3323D8F3619C5CC1EAEB2893BDE4110E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028688Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:36.759{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB1D8995518F62A98FF8343E18ED3A98,SHA256=E91BA3D842C96A7195FD7ECFD1EAAC9BB6C8B0C2DEABC869BD3D6BAB6D38EF1D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040871Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:36.115{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F86BEC949A8A9EE348410DA8B53FE2CD,SHA256=AA12577CABA957CAF3472845D3B27F4D3A9065F0EA47C00E08BFE176B9039B65,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028687Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:36.009{6F8252D3-7863-616D-C406-000000000502}1852360C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028690Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:37.822{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C08C71057C95554F872060587205EC11,SHA256=BB143724271CAA12E0EE88D3BEBB8DC14ED0607BFB145B7E6502953462FF7DBC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040872Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:37.146{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C77FA8183C5002F7CC8D4A1C54510C6,SHA256=082FB8397AED9664B40807E7E6F51DF4824528714FEF6C3AAC364D7126BBD7E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028691Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:38.838{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B7378A718DFAF10F1F47C6F70E227EFD,SHA256=73004DDEF0D909F5EBF6BC97406A28D9EF85596F0059A533541CC0441353E796,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040874Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:37.098{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58963-false10.0.1.12-8000- 23542300x800000000000000040873Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:38.380{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=60F8EAB3145936AA9B03B3031B9E25B6,SHA256=CF0F85905D4E2A6239E6DB2EFBBA6D874A93E2885FD9F00D5FDF080ECA0D4816,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028692Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:39.853{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6549E0B02E024DF20217DA987B88E674,SHA256=629D951F2C9BBCB9CF1829BCC3F2DB566863BC7A324F8C344879094490256854,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040875Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:39.411{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3E463BD621DE5D1D9E2F92D0B604F6DF,SHA256=58AC2018FCCD57E82FE119B1AFB37D365620E5C47593059F0F13AEEB37A07486,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028694Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:40.869{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BBA6FE9A2D6E974582836AFF6B1AC849,SHA256=6466712520EB0899FD367CAD99E515F2DA88DAC5C7E8F5B4EC6221E7869DFAA3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040876Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:40.630{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3D47CCEF6BB0B356C7D6CDEB252224F,SHA256=56763BAA7EFBB90B7A37477AF7ADACEA897A2230DB4B5BC4CBF9717D4707AAFA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028693Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:37.800{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51111-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028695Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:41.884{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D284268DADC74463A5963721E4BD8C80,SHA256=233D699BC8762A2869B26062ED267F45AF5D58299E130032208BE3258D7B126C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040877Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:41.677{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F93118A583AACD2F525C0DB0879BB122,SHA256=BEF63EBE87059D74F35AAF647D988F6E2612A4E620232CDBE553625035EF9662,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028697Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:42.886{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24D7B9E24D4F27C3F5991F42C7241C18,SHA256=8D30440CDE795231493749F740840A6B7867503F7675B0FB44BE0CFACBB67C89,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040878Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:42.708{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9AD405AB497B23A0357CFF901467858,SHA256=5D0BB1D950E1014074A001060F07286CE5068F017081F9BC75DDEAB3A0EA177F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028696Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:42.482{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-110MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040879Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:43.740{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB249A4D72A71DCD5C4775EB708B1D80,SHA256=3A260AF291734B09E927677775663E57D765E80A4DE4B4DA38B881FFC1353387,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028699Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:43.915{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=12574976EBB2EF080DF4FAF9A68AC533,SHA256=D20A03DF9C5D2694C9E10636EC319FF152643699959C773DA6D04E3705FB1EE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028698Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:43.496{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-111MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028700Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:44.918{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B66B46F4FDF5DA04626BC69D16F07640,SHA256=E069298A4DC70A990E29A4A49CFF6AA0E3803A2820A768EB6B2621C9C97EE0B9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040885Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:44.786{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4BF10DBEBD99A6F66A2FF35BDE4658C0,SHA256=8F800DC0A18B1CC5BD3C15B3E4D05D9798D85724E00398B79A9282AF4EBB3F2A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040884Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:43.051{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58964-false10.0.1.12-8000- 354300x800000000000000040883Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:42.383{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-185.attackrange.local53domainfalse10.0.1.14win-dc-185.attackrange.local49872- 354300x800000000000000040882Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:42.382{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-185.attackrange.local53domainfalse10.0.1.14win-dc-185.attackrange.local53010- 354300x800000000000000040881Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:42.382{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local57706- 354300x800000000000000040880Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:42.381{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local55138- 23542300x800000000000000028702Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:45.933{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A2075EAA6A5FB8954FEEA723B6861DA0,SHA256=0F1230888D1CE9E3C2A27B3AFE1454D26437D1CBDBDFB5EB6EF35B5DD6808571,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040886Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:45.802{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7E156882932932330FFFC83D5510685A,SHA256=F191F589312763711DF60E0E40BA73CA7CD1F9E2C403A88569AB10EA358B57CE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028701Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:43.770{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51112-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028703Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:46.950{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2AEF14A9C2E969FB400DD51737791039,SHA256=8FC65D16975BFD66D545B221E0B0ADA4BC94741F21F1B04D205CB651E64F7FAA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040887Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:46.818{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D77B6D440056707831CBC331538C62A8,SHA256=F1B10956498B571B1CE2C62C93881166561C7D653885AF4E2F4EE314D3651923,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040888Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:47.818{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=33971D9FAB079DF90A276D7CEDB73DB7,SHA256=053EB04FFD347D74E6BDDFE26BD992BF9FBC89A3C0E90B11D2CEEEBFB1CBCBC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028704Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:47.963{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC5851A86BE6BF57C9045AB18F038D24,SHA256=75C0DAC29AE0EB746995FCCD80E38BABF35EB3E14559C06FD37C85CD446E9052,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028705Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:48.978{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B0202DB915F56EDAA66611A9A72E06E,SHA256=74EF87AA82EF3B12AAD0FCD2AE33FF4328B728A2D8DAAFE759BAB0EA3A573B8A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040889Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:48.833{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9238C33DD77DA1E148C5C20D9ED76EAB,SHA256=C50980B475EC5BB93C431F7EBF6A43AEFAC8EDDA0297F2BC2E5E1409454F4271,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040890Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:49.849{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3E189E3652EB96FF8739E77FF561392B,SHA256=249E4D5FD92D60D67412E5BE9CF6FE7254140BCD2FDEF255C04A8E316E735704,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040892Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:49.035{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58965-false10.0.1.12-8000- 23542300x800000000000000040891Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:50.865{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=007DCF012169CEE49CDDADD8A46DE962,SHA256=095BE6B148AA3BC8AF562F832FC893F66A89FCCD68F24780CC42FF3AC10B9DA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028706Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:50.010{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=630088ACBA8D713F3D258AA219FA4F78,SHA256=A84F938E467200CE27296DB0022D4E3E7696FAFAC2F57BA5063D75BC77FD49AF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040893Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:51.880{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2211AA61050DD22F0127B4C5C6C7BD4,SHA256=43234BD640D8FB731EC72422620C0EBBCEE864F4CD9067045DF3E25215B6ECBC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028709Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:48.815{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51113-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028708Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:51.806{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=31D210BB0B7820ECEAE07E8E669C6B89,SHA256=6B060BA3D748CE356009DF7AE1EAFE938712AE9DD408B10AE9A9C4C6AEDADBFF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028707Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:51.056{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBC1E5BC2423096314775DE87C0F96F5,SHA256=FBAD42160411C18457569692763EE540FA3266933C4E006520AB5C2031E1EAD4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040894Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:52.896{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=43FAD5B4D1EEF66BEE33F229E402A66E,SHA256=3BB19BF304FB89BEAA90C1A064FA1ADF9E9A4F2B82785143A38C8B236229A00F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028710Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:52.072{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F8405ED16F170129E6205DDFC44429B,SHA256=AB381E116ED629A4F71A2493BCD23332240B71713A63981AFE554E79C999A272,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040895Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:53.912{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D10E34BC49B64785134F330853F9A33A,SHA256=8268F54BAF53CB7D365EC1410FA98465E5A8B313F6CC19BE8C11E305BCF62C84,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028711Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:53.088{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=444149516DBE3A2274633AB1170BE17F,SHA256=DA4408067CED4F979E3313C3F62AF4064D3B3153CB224B9A5B05BE210666A569,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040896Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:54.927{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3169D583E1AC197A6A27CD29E9C1D75D,SHA256=281522201057E19C43F68E8E1056E887F939D599AF816D2E2598D0D9EE0F080F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028712Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:54.103{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3BE47B21D055968ADEABF39CB1CEBAEC,SHA256=F8F586899BE7BEA7563147197DDA040D05D32A63086E1ACA71400974D7E7CA17,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040897Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:55.943{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E9FEE04AC01AA8523D2F71BAA591A018,SHA256=6C1F5990DD155D8478CF79B2FB5472E92BCA661E4C0B00D90319D2FC442C1FFF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028713Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:55.119{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8DF091FD859D739D17822A68782CE2B3,SHA256=2FF2869B5B289699A65B9BC97988A7BA125B8256C30153AD3ABA61A508895612,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040899Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:56.958{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=107D4A1B4FBF7BF85542E5116217D79C,SHA256=FE7D18051A1CA41722BA20B8468F327F5D85A433F466F3D0A9AAE7DD8F9FC573,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028714Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:56.134{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=739FD17C4ECD740C50D3CD5D82EA3353,SHA256=5F416B16C96249D8580CB80FD0CB35B8FC839F58CABC76ED24B00B095176BBCC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040898Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:54.066{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58966-false10.0.1.12-8000- 23542300x800000000000000040900Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:57.974{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F95C63FBDF1AB8D6B2367FC842F8B433,SHA256=6BACA324A967B4161F502EC90907E2A32BEB4D6DFD32D6D68A5731CECE0E6BF9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028716Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:57.213{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=905DE6A9430B0BF624EDA04A05B9ABA6,SHA256=DB459A2EBBC65C20468C233CBFB0A13856E9159EED38B608F07ADB2E687F07A5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028715Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:54.706{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51114-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000040901Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:58.990{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7B58A490355016C84378D215A39B7F3,SHA256=B4D4B6A15569D09B26E820D53E0691B53F63075D0AC57BA77488F01DEB9C992F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028717Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:58.228{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A86631C02FA730AA8D372507ED209A7,SHA256=6B88D9E07161B96F30536C029F50E278A142B9DA41D3CFBC7759C66F1A71956B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028718Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:59.259{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B7FA6C8A2C89F9EF5202303E29658276,SHA256=17EEA0F9D22BE2ED61572DADC2FB615427D3FF0F3C370AB003DE0942ECF2FA41,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028719Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:00.275{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B544C68169109CEFD3832B7EC851E576,SHA256=5554C31ED388B34360F4F8D8D587793DF72507C6A1691A5125D08FB5A63D63CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040902Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:00.005{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=59438EE0CA6ED83FBA161A9B7E5E9197,SHA256=19613AF82B90F9BA38ECFC76EF17944A5A7FF7E91BE8FA2A6BCE1EAF65F9917A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040904Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:36:59.129{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58967-false10.0.1.12-8000- 23542300x800000000000000040903Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:01.021{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9E834F1B5E35AFA610A143DCD75F48BB,SHA256=AC4167AD6CB6D83AB458E6E05452226736FCF281E20ED770E6233AD3ED9811D2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028720Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:01.291{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44DC23028A8614594E4B7BD982190E44,SHA256=D0C0EF2024B590AD4F7CF530DED4226E44CC170A508F21ECD45D8E72C86A5DC2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028722Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:02.306{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39B785D051FAFE440D27864D55D31A9B,SHA256=E7E52B6A13DCCDBF60B292267E93D497A7A955722C7D032E90E3D4DD2114A388,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028721Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:36:59.784{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51115-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000040906Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:02.677{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=C521FFCE281755E801184C77A6E5A03F,SHA256=AF250DC759B9F98B12BA65E41E3215EF9A12A8FB0FB00C0C9333342E0F8F8FD1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040905Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:02.036{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F853655A3E1106C077B7DD180C1D34F,SHA256=B7DFA964AF3467425091BE243B1B5B3034CD4DF9595D16B3F1C67E80FE711A32,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028723Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:03.353{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21364C6235567511018089DC55FCEB4E,SHA256=9FE7B88F89D22B1E441D58421831FAAFCEEB1AF1544194B7E3F1FDB25638FEE6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040907Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:03.052{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A086D6A3F44C1A836AE68B62494C3C9B,SHA256=8B6320B2405E80C4661A5CF977203EC6E5D7791B3D37F05AB23F618E3187CB06,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028724Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:04.369{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15C35EEF0C06D13C5BC8889658366026,SHA256=36C16F98837B0C680AEC73CDADC5E44E3648DA42C418981F048216966EA34400,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040908Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:04.068{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E65E4A34A83F523351CA6D9A44DF7413,SHA256=CD12B448469D752CDD089954BE7FB2E960BC5AFFAC076641C1D1847E5091F146,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040909Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:05.083{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BBA8E399D0169BE2447BD08456211905,SHA256=777689601B2CDFD9F5CBC27DAB1D2C7104D27B185C2178A2DBE6559D68C288C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028725Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:05.369{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D799DB1A518DF8D80C77A08CEE399D63,SHA256=528587F77301574026CEB84047EFFD6E63C86E37F474282FAD25446101DDB696,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028726Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:06.384{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1AF64A1ADD3CF51CBF8A69B3868627F5,SHA256=BA2126A9F70785C81A0CF2E7F7004C7647931720099C28D58A751F42DA354CA4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040937Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7882-616D-0009-000000000402}2920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040936Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040935Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040934Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040933Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040932Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040931Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040930Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040929Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040928Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040927Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7882-616D-0009-000000000402}2920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040926Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.818{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7882-616D-0009-000000000402}2920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040925Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.819{8D4DD44E-7882-616D-0009-000000000402}2920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000040924Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:04.988{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58968-false10.0.1.12-8000- 10341000x800000000000000040923Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7882-616D-FF08-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040922Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040921Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040920Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040919Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040918Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040917Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040916Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040915Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040914Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040913Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7882-616D-FF08-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040912Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7882-616D-FF08-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040911Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.318{8D4DD44E-7882-616D-FF08-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040910Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:06.099{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2066AF9201951A97A6C4866903EBA0E,SHA256=ED53A59A7BB3F20D2F32B46B3C29958F168D8249F24B86322E80152CCD2F2908,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028728Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:05.799{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51116-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028727Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:07.402{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E343AEBD3F3CE87DA76CD80E5C35F8AE,SHA256=0E8E42AE96FE08D72C55748591EA8D524305ABEF2BB9796761B37167373BCCDD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040955Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.663{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040954Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.493{8D4DD44E-7883-616D-0109-000000000402}39923804C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040953Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7883-616D-0109-000000000402}3992C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040952Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040951Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040950Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040949Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040948Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040947Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040946Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040945Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040944Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040943Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7883-616D-0109-000000000402}3992C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040942Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.335{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7883-616D-0109-000000000402}3992C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040941Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.336{8D4DD44E-7883-616D-0109-000000000402}3992C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040940Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.320{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B3B481CF07CD8D6A20C87153E299160A,SHA256=C4AB8E48DD8E96A5CF88DAD0F09058900DEEAC3934F84D4EB1969E3BDF2526C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040939Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.320{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2088C4CCDF708425002F972B9EC12E66,SHA256=2D48E6BCC6FAD8A0C8E95D9F3E7B5AC939703048A0795626778F0F62985E2324,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040938Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.195{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=25899F4EC6BE2CB2B03A41BF350EDD30,SHA256=12AD09D5937A1E04C8AC7605AEEE09A4E627AC9371E1C363E95911C8F8522BDA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028730Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:08.402{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E98889F6DB7EDCE9D5F6A90EF099DC57,SHA256=30AFF4678448D825FB0F98674EB192C79C82DEC502326B0E47F66BF6D076B36E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040971Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.632{8D4DD44E-7884-616D-0209-000000000402}44084252C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040970Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7884-616D-0209-000000000402}4408C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040969Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040968Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040967Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040966Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040965Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040964Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040963Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040962Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7884-616D-0209-000000000402}4408C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040961Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040960Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040959Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.460{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7884-616D-0209-000000000402}4408C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040958Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.462{8D4DD44E-7884-616D-0209-000000000402}4408C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040957Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.413{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B3B481CF07CD8D6A20C87153E299160A,SHA256=C4AB8E48DD8E96A5CF88DAD0F09058900DEEAC3934F84D4EB1969E3BDF2526C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000040956Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:08.351{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5319193977965C873F8BA529702BDF05,SHA256=6F67494C7E01BCFD291038714F17612225031237226D35A6F82DB535B6261705,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028729Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:08.308{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028731Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:09.433{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA889215D12D2979EF4CC831153DC94F,SHA256=BD1730E60DD89B8E1ED02121D08CE0ADC5613215803447035DA67B6D99DC1BED,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000040988Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:07.521{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58969-false10.0.1.12-8089- 10341000x800000000000000040987Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.617{8D4DD44E-7885-616D-0309-000000000402}26604428C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000040986Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.476{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=54EDB30E0E582B2C93B504379A0A09CE,SHA256=220530E3CE834A33E1A827837A82D0477B48E9D352B74BDAD3B0D9582281A62D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000040985Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7885-616D-0309-000000000402}2660C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040984Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040983Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040982Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040981Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040980Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040979Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040978Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040977Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040976Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040975Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7885-616D-0309-000000000402}2660C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040974Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.429{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7885-616D-0309-000000000402}2660C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040973Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.430{8D4DD44E-7885-616D-0309-000000000402}2660C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000040972Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:09.367{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=857055EEC2E5E7A8A9BB193E7790F7A3,SHA256=3FDEE5C0DE3EE3A209BA0E533FB955EDA6D43D45E67041BE50FB2CCC745BA7DA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041003Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.726{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E710995759E35535635F9F0B77FC5E12,SHA256=35FAA89B7B955A359BACA2D9C3F7A6014C0038D55718A19E6F88DECF53964E8F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028733Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:10.449{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FB4BF21BD8C4A2E0BB7364DD5E58821F,SHA256=AD3A0C2A9FBD5899DAB1A0749B66367EF75AB9E6ADA17892264646A304F963A3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028732Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:07.848{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51117-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 10341000x800000000000000041002Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.273{8D4DD44E-7886-616D-0409-000000000402}50604992C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041001Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7886-616D-0409-000000000402}5060C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041000Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040999Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040998Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040997Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040996Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040995Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040994Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040993Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040992Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000040991Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7886-616D-0409-000000000402}5060C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000040990Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.101{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7886-616D-0409-000000000402}5060C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000040989Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.102{8D4DD44E-7886-616D-0409-000000000402}5060C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041019Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7887-616D-0509-000000000402}2568C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041018Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041017Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041016Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041015Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041014Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041013Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041012Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041011Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041010Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041009Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7887-616D-0509-000000000402}2568C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041008Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.976{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7887-616D-0509-000000000402}2568C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041007Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.977{8D4DD44E-7887-616D-0509-000000000402}2568C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000041006Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:10.100{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58970-false10.0.1.12-8000- 23542300x800000000000000041005Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.788{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2852736213E71E751FAB14A304ECDE46,SHA256=CAAE6C5F18760DF9B811A16B05941B0408848185BBB020364B4F2E84E33635AB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028734Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:11.558{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=720C2B8F858B938EE06DD91D16A5C801,SHA256=1ABC9C54A6C9FB218826B75BDDBC2BFC8D43A8412E1DC9115207BDD73BEA1785,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041004Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:11.148{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=AC2B814034DD340E487E6C0172531EF2,SHA256=381BEC85ED32544FCA62D08BD73169F6D07E9F9265A50020EFD3FAB3AAE17129,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041021Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:12.976{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4EBAB8333ED51049A0E8DE2DA63BECC4,SHA256=172BF4C736B9A381D96DC58A7DDD5FF1D525A2BD6A4A08AD148C185F25E20799,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041020Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:12.835{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=59FA6415E96CC4FD0E153BAD97E9783D,SHA256=485ADA7165BCD2840E6632DFFBCC497D67CD6D254C62B17F3F1CBEA62E61A63B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028735Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:12.574{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3CCEEF60098134D81C4E700DA5B7DB98,SHA256=ECD2F06D394EB0A31A96AB8876404482366C32E14F7712C1FDDF6FA82F563951,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041022Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:13.851{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D825AC306B7E08A7D62E3A80EA79ABCC,SHA256=68098E1DCFEE419652F02C32FF37989932D7A9C034289D2EC55CE6E72F167BD3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028737Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:13.605{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF8FFFEC23917FFF5FDD835FEFE79BB2,SHA256=874C3E91D6CC8FC3D6C2105C4C900192BA36ECBF16433E14F520665C78C6FF26,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028736Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:10.801{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51118-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041023Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:14.882{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2D14AF0E447817B86FE178A08EAA75C9,SHA256=72EFBCDF5ED1E9D4673CC62B14AF7CBC875D78C396F63171A7EB7A58A419D1CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028738Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:14.636{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C95CB08EA60FF59580BB8CA33FF16EFD,SHA256=C453A7CE625D1308CD54B1917ABDC09A4A68567AD7BCB853CAECB90A7FA64A8F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028739Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:15.652{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=381180DF937C6BB56E02111E10B03FEE,SHA256=B9F861C06CDBBE18D65C8B93C38CAE3C94B8F49C82444A2DBCC1AE78CED68B14,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028740Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:16.668{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A72F1214E491C8BDBEDD5496D85C8147,SHA256=458778ACABFD2A6961E67D188A78FDF24E520938D85420FDDA5531FFE5B422A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041024Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:16.101{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDC4C28AE1D04834524BE54E2C046866,SHA256=7ACC15D2D8897A47B2027FC00573B52E2EB27C0E473F132749EF78EC71354235,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028741Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:17.683{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=312876537B84C35B8488BDC960FB89B3,SHA256=11B655AC788C1EBE927AE9D4A1D7DD76E4F1E2C239182F27AAA4C15E24554F89,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041026Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:16.069{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58971-false10.0.1.12-8000- 23542300x800000000000000041025Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:17.163{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A51514E4581DEF7A4C0F76AD2653696C,SHA256=BDBB13B87515F65DA2854AEA628166DA23EDAD31D05AA1AE7DE74FA2AA365173,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028742Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:18.761{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=807CFC9CF797789A6CF33652EC507125,SHA256=BCDE283B46E3CC243C91D97707A9D8A77C6D1E027CD3E50140164901608D5672,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041027Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:18.195{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21A011D9CECE85C013D3C8F6D0F946A8,SHA256=80FF2B71309FFD6E672CD579F29413AF5DD09210BBC4AB79D038BBECCE0D937E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028744Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:19.777{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9F1AAC2D1D879357450E8FC2ADBAEF0B,SHA256=06C267BD13E9DCAE763A6C354D6053789CD806466AB8556EBDF310684307ECC3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041028Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:19.226{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0552104C7EE96A3F852D05078019D6A,SHA256=5D6697C93A07378EAAC3D373D4EB3432393D098D2DD67F6F2242853E86357957,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028743Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:16.660{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51119-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028745Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:20.808{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F2FDFA0DE3BBA90AECB789814891F54,SHA256=ED651445EEB0A0492DF600BCC79BD8F16B039FC1988D3BCC61669CE21598C501,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041029Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:20.273{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16E5722F547A50C0821BDF5A6D057C54,SHA256=E6E72238D5621B3549F059771072D7E266CF8F7D407026690966CD8249C2CEE5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028746Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:21.824{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=551283FDE4D73AE8A843CE0DC0FBB747,SHA256=368DA9D01758A0B96237C6C7346A1072CCDFB45CA37825AEA58D56B2744CE21F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041030Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:21.289{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53BDE593CCE1A3267560602C60514B5F,SHA256=EBE2675B3D031944718A97C98E66B8DD419EC886BF1CDB2D2B3D48C2D2B216AD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028747Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:22.855{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB8CC93BA296B787B4A6681432C54292,SHA256=1401034D7C2AD7491D986365303A505F8355348092BDCC150F2B93D81F2C951C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041032Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:22.307{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-119MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041031Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:22.290{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C68B3B6CD45C7CE9374A9B7508CB136,SHA256=18C1ED9F922BA649B164996993D74357ACCD9D3DB5E1DE3DA43B748F84C52161,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028749Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:23.871{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=51FD886A81F06B112864158CDE61E19D,SHA256=E2AD8A077CFF66F1B22E8053CB17555B1B84DEE27407BA44AB6D47A3646B1182,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028748Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:21.678{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51120-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041034Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:23.310{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-120MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041033Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:23.295{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EAEF77C2FCA56A79B81E02DF914BED15,SHA256=D1966EE8DC1282432F409F1FA58B44325FBF01894CCF7132CA4E7CAABEBDE25B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028751Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:24.886{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=94C272D4B4A75047ECA95EF92A5AFBE2,SHA256=ECA5F9C8B0E696405EE3F97A85ED68182432A0EBC41500D3C47D3C0971574E22,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041036Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:24.295{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2D288693A9070E444A229479CE5326A,SHA256=462C1D91E96A9947D96D5FAFAD416A953C44FB323328407CD5AE5955445F4C33,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041035Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:21.991{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58972-false10.0.1.12-8000- 13241300x800000000000000028750Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:37:24.683{6F8252D3-5DBA-616D-1200-000000000502}288C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7c425-0x48e9d73c) 23542300x800000000000000028752Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:25.933{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=106C8C42FE8B573D22D2B22BB9547321,SHA256=78BBAA0E59B24E3FD2B58AB2285A34461A949B0E97C539CB583EECF409942F16,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041037Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:25.327{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=33CB97FD309447DC9E13E9BA0F4AA67E,SHA256=328D84C4124E381F5BD14A833F3D5DA427D61A81C8C68D5CEB362D5310DC2F63,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028753Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:26.952{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AED22DB4A7D4F975EDB2E212884982B4,SHA256=6BF1D30DD3C0A22B5530894785DF45011F99CAF2E0FAA51707C3B0B686119F67,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041038Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:26.342{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2FAA947E5A708BE50902526277D7D9F6,SHA256=EA1AA25DDFB9FF67BE5639F490DF46C58881C4C951EFE0D3C066DEFFB65F57D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028754Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:27.967{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6A911E080B5E24D89B36CC2BC1013ABC,SHA256=D0087FBBE893906596831C468F2352140A10A85835095D6BEE5579527920F36B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041039Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:27.401{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=96386C941E2B9EAE74F1B836DB667984,SHA256=8AA309D46F858BA37F57123A7CB7A63E8F67F82CAB715FC2679763A104B4A461,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041040Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:28.447{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3F2B3D6DC01BC6BACB3EADCB9188D80E,SHA256=ECC9F099EFC14175C4BB1B2A63CFC6ACAE5C38176A88F378BFCD7F35487BC6A5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028755Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:26.694{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51121-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041042Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:29.682{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=722D1FE7620D906B17EE7E67A05AA28E,SHA256=D9A5883616DDAED1D6C452A27389294DE39BE8F240744966C3AE022266A696B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028756Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:28.998{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08FD3095D7CFF9EDE75BEB96C2D140C9,SHA256=7EF86F612621B8202C4E9B27837BA105320AA7BB2062FB9AFDE75A321F6C188F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041041Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:27.008{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58973-false10.0.1.12-8000- 23542300x800000000000000041043Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:30.697{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1FB82CB4AEB2AE7F6566A1EED870D25E,SHA256=355631D9F46F034890C062A872EADA86D9FA5D279D32F8F75ABAC5B5636AD89D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028757Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:30.030{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=083D468F2F0AC5BF22C650CB2AD62D41,SHA256=43475EB4116DEB72DFEF8AF1A654B1722C7B45EDDC2A94A6D9B13DE5EB597471,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041044Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:31.760{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D44ADCC3CE69A7CDB7A02E0B141BB05F,SHA256=735AAAD9912E0B640EB5B06CFFA0C3B155E679734FDFC2585F1DD31AF9DB5C18,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028772Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.592{6F8252D3-789B-616D-C506-000000000502}17481340C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028771Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-789B-616D-C506-000000000502}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028770Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028769Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028768Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028767Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028766Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028765Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028764Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028763Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028762Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028761Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-789B-616D-C506-000000000502}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028760Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.420{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-789B-616D-C506-000000000502}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028759Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.421{6F8252D3-789B-616D-C506-000000000502}1748C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028758Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.061{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCECC7BCC1FF2F35BD837E02C8F396B1,SHA256=FCCC9239DB8932F80C881E30BDCF66CB2BC813A3BD031918DF4D8FD8DAB94FA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041045Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:32.994{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB058A83E405EF605664DD10F7C7FA70,SHA256=F7EDC8BAB290D3948EED3A0C027AD290A7A4C449B2D8BD6D6B9B7277BD3263F3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028801Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028800Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028799Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-789C-616D-C706-000000000502}1780C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028798Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028797Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028796Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028795Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028794Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028793Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028792Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028791Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-789C-616D-C706-000000000502}1780C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028790Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.764{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-789C-616D-C706-000000000502}1780C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028789Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.765{6F8252D3-789C-616D-C706-000000000502}1780C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028788Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.436{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=25F5F6281B355F0018EBDA7BBFF4F2CA,SHA256=B4B74104E53965804E4C3142FEEE2C9CB2403B6DC9B2B07EF458FF455DD78542,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028787Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.436{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5829AC21D140016CCDBEC5989A7E03B5,SHA256=5F496752AD8B6FBE15ACCCF8D915FA7D2CE868F0D03BF4FCD28420DB78C729ED,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028786Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5D8BB12D867F56BFC72399D48B62F8A2,SHA256=EB952E25BD8E6715024AD5ED182950453F5F54824F4CB31400E088CE162A52DD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028785Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-789C-616D-C606-000000000502}3828C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028784Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028783Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028782Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028781Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028780Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028779Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028778Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028777Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028776Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028775Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-789C-616D-C606-000000000502}3828C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028774Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.092{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-789C-616D-C606-000000000502}3828C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028773Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:32.093{6F8252D3-789C-616D-C606-000000000502}3828C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000028817Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.842{6F8252D3-789D-616D-C806-000000000502}14724036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028816Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.827{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=25F5F6281B355F0018EBDA7BBFF4F2CA,SHA256=B4B74104E53965804E4C3142FEEE2C9CB2403B6DC9B2B07EF458FF455DD78542,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028815Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.608{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F159D39C241F2C2F258139BA2D3F6DAD,SHA256=0E1293AB6278D9634ACA43AFC99FF3850C723C291528F5589337637D87C88294,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028814Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-789D-616D-C806-000000000502}1472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028813Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028812Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028811Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028810Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028809Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028808Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028807Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028806Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028805Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028804Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-789D-616D-C806-000000000502}1472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028803Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-789D-616D-C806-000000000502}1472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028802Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:33.577{6F8252D3-789D-616D-C806-000000000502}1472C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000041049Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:31.930{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58974-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000041048Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:31.930{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58974-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000041047Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:33.072{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E856DB5E3789FD356E9C7A03FE985CA6,SHA256=BCF979EF826BFB8D06B748F2449B71B15F60F87CB64E7456DEB7DE2CB3B8FEB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041046Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:33.072{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7B942E16466AE8E6F6DCDA2C2B1C3BD7,SHA256=347FA5F9CFA3BA685CB99211A4AFC38AD20F46879B41C3DE50F9FDD175B65ABD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028833Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.936{6F8252D3-789E-616D-C906-000000000502}35961888C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028832Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-789E-616D-C906-000000000502}3596C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028831Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028830Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028829Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028828Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028827Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028826Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028825Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028824Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028823Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028822Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-789E-616D-C906-000000000502}3596C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028821Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-789E-616D-C906-000000000502}3596C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028820Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.780{6F8252D3-789E-616D-C906-000000000502}3596C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028819Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:34.592{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=019C752270F0BD0BF42B7B6E00EE3A1C,SHA256=83EDFDD9963B36BA6AFBA3A6C90A465F2CFFB0F4D0AFF9BDA9F7622E5AA3654A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041051Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:33.024{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58975-false10.0.1.12-8000- 23542300x800000000000000041050Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:34.025{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5EAF688C58FDA851B7398906B993E2AB,SHA256=B962F57F77C2EF771BB4E99E4575CA060C38C43320CF0AF2E5F985E40EC332B1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028818Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:31.741{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51122-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000028847Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.609{6F8252D3-789F-616D-CA06-000000000502}40242656C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041052Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:35.041{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B13DE483C817F26744F8AE336133B1ED,SHA256=D1A45BB99374FC54AAC9CE1B4B94D4BF23517D06160EE586E503A20CB5BCCA9F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028846Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-789F-616D-CA06-000000000502}4024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028845Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028844Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028843Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028842Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028841Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028840Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028839Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028838Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028837Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028836Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-789F-616D-CA06-000000000502}4024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028835Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.451{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-789F-616D-CA06-000000000502}4024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028834Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:35.452{6F8252D3-789F-616D-CA06-000000000502}4024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028863Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.623{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=738FCB616624D865359FED47B89F7130,SHA256=7C72A1B2ED6DC140C625E883ACE3472FB5C6939EA4137C539356AF2CB3B819DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041053Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:36.072{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E45C3D925235D0A4B6DF222BDC883A19,SHA256=4E3D6DCEDF612232A0FF38FE2F102A20D9D75AD38416CF50E419A4AED10349A8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028862Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3CD22B746F9F716430CA714EB73C9716,SHA256=273DA45DB173C76FA8CAC923253EE3EB00CEFC96F30FC216A5019928CFE0BE2A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028861Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78A0-616D-CB06-000000000502}184C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028860Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=992A45D71994B7D832C8A430A674F985,SHA256=386B0EF2035547EBDD3A28761EEE9E0BA76909A95B05D11153D5FAE67FC5705E,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028859Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028858Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028857Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028856Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028855Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028854Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028853Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028852Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028851Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028850Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-78A0-616D-CB06-000000000502}184C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028849Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.123{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78A0-616D-CB06-000000000502}184C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028848Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:36.124{6F8252D3-78A0-616D-CB06-000000000502}184C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028865Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:37.639{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D091E06CDA3BB723A88912BD376930EA,SHA256=1D044D89EDED85CD5442A9378C97DDCD03A34F28510D8E9EA4EC4C6CDF264AE6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041054Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:37.182{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC067B6551B9A4461372A207630B6BBD,SHA256=A9C8B03B722B05BA0EAFB7FB73DA96074D1267DC96F578E95C303C3F755C785E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028864Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:37.233{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=91B359B8B2EFB2E9D7616FCD75FA8A84,SHA256=5D6A4988493D684F772BDAAB0FAE66628522CBA51568210CADCF9ABC44F9F63B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028866Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:38.655{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=643E871516C1ACFF2BAD62826D7B58B4,SHA256=C21807452FD0259630D3CEE41CAE0A95291B0BBC959322C254FDF46F61F0FB06,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041055Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:38.213{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E855A5028ABD978AD9A6C7D1B4E07499,SHA256=ED6FF289B7458780C4F301608F7F545F347C593AF373F34D9337FA0C84D8334C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028868Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:39.670{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6D2F488275F9E9A287BA9D7DFC586B5C,SHA256=FA2DA1B4A4BE81A331F64671A13C748904ACAAF0A336BD35C2DFF4A573DA75D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041056Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:39.291{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9782FB092A5E1F81ABD00BED5A0A58B,SHA256=BED7B8FFBCC9C68CFE6C20D803FD991B219043C28AD9DEF4F020E9BE15A0F1D8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028867Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:37.709{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51123-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028869Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:40.686{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3138F25E46988202FFF811ECEBE03117,SHA256=44664C154D96DC667F098DDE45B778C747805E5C31C1AFC0ACF13F1222F26338,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041058Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:38.977{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58976-false10.0.1.12-8000- 23542300x800000000000000041057Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:40.322{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27C1B762B68E724AC399F0EC9369D8BB,SHA256=6557335FB7CBCC2D2B5DDABC6C8712B1CE23E61CDBE25C0EA13A233AE0706961,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028870Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:41.701{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7866008831DB74803BD3CED04B12C1FD,SHA256=000B89AA3A122A5B97C40A6C857AD1970D8E374F6395662E644D82AD44D4348B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041059Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:41.338{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39A9BC57A2E3AD196F59EB0D935FF5C9,SHA256=A55867C0B2779B583C4FEA03E66017840D0FCFEF95BDA85C483B96157E08C0CB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028871Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:42.717{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C3B0DDA9FBEB2A2CFD1F2876308ADC4,SHA256=6CB977FC0784D66F717B969167E1D7412800E3060A7820945966CD742CD2FB56,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041060Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:42.510{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9E8A769FC19D8EC20F1667BD009C8E47,SHA256=C11D36CB81E37A3D82EF484C9E28A278ADDA7A8BC9408A146BA3FC85FAE60F7D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028872Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:43.719{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D1F390A46A5A52ED8C92C276F261F10,SHA256=D21118AC4E62B95674A33CACE7DBB3ED96C73CFEC7659D83B6533805AE8714C4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041061Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:43.525{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3CAC1868C96E9F7DB6966228A26B2187,SHA256=7D97ABE26B7E6520EFA28DE7723D09002648DA787B7C95920D6965B260A344E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041064Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:44.572{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE11659E115C73B83A0A953E2C9EE400,SHA256=2F98EBF833B430C57D85BB1661D295AB77D753EA67FD8CFA10BCE31C96729B64,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028875Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:44.725{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B11DF52E1B05422C35F31847EF59C970,SHA256=D31E77E0BC424A4F661935745EAAEFBA2722205E800647A8912A5CBEBFDFAF98,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028874Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:42.819{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51124-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028873Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:44.019{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-111MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041063Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:44.525{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3799F3DD1AA78FF3AEDE01B910D54866,SHA256=094682E9BD73BCE69798CCBF22E02EDFDE21225DB3CEFADC1C5DF6FA877E0147,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041062Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:44.525{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E856DB5E3789FD356E9C7A03FE985CA6,SHA256=BCF979EF826BFB8D06B748F2449B71B15F60F87CB64E7456DEB7DE2CB3B8FEB3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041066Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:44.118{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58977-false10.0.1.12-8000- 23542300x800000000000000041065Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:45.588{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D1B442DFD7E694C84874C7AC54E0F73,SHA256=44D09C1511EA63C7F78B850526A0363E51CA3FF106E57A748135E37EC96604A9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028877Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:45.740{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E9E15B07AF15AE0A93AA92583CAF56B7,SHA256=EC028DDC3705BEFAFAFE61BCD1F7BD01C3E5A439532EC5D8764D2F10C9E85768,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028876Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:45.023{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-112MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041067Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:46.760{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5189B27A5E6C507706874A51DDF7B36B,SHA256=6E81ADD16FA310B9AEBB731E151C35EB299C60B85BBB3A2DA2527960E91756EB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028878Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:46.772{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=375042FAE0040DF63E181A376BCAF995,SHA256=B86A37DDB29584176A417DC7D84AF7FABEA6A469D43409D0380EA12663D80A7D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041068Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:47.769{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18048E23AB3E53AB1FA4377B35DCE05E,SHA256=A48C3F73AE6A7754D530C970AFCFE818762E2A7AA2AB6E573A34FE9B009C3023,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028879Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:47.804{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1643DE72D4808EF9C21B22E61982D38,SHA256=003FCFE3FE7AFA542B423FB04ECAFC4F29F6ED276F60AA73F3D63A129488D82A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028880Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:48.820{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=33B8AB7130A4BAEB59A3A6FF6F4E4A2C,SHA256=90011D566E6FECA9C2C400B62D1113B166D698D5378023764DD323F4ECAC91B6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041069Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:48.785{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E1020774EB25F3E8AAE0E0917F6B049,SHA256=B9C538F46A15069878A5FC91D90995F5DEE1D6AE30D3F744937751C9204E39DE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041070Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:49.801{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=79FEAA7CC73C11142C6D776234ED13B7,SHA256=43BDB46EE581224E42A431E89A46854C93A8BC49F8B6E98577361B33EEC5550A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028881Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:49.835{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5A1F32630EDF9ECFF055172E7B488A6E,SHA256=9E5E444292817A0809F46564213FE34BA91FA927815F46FA1903071058864192,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041071Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:50.863{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE8A0615912E3B15F1B248EAFDACBC6D,SHA256=A0F9DD0FB8B1105609C23CBD912D1C326500A664186093E717448D188C5F9E72,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028883Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:50.867{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C950D1FBA4AE5E6057900E55CFA2AB8,SHA256=35359D6AC513B6C8424A19664AD95D86AFB77F5B3227B8E7E7E324C5B7C5A95A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028882Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:48.781{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51125-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041072Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:51.879{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0CBB78DFD52F0ECDD33AF4D2D780EBA,SHA256=B46AB4C56AE41A468E77806F00504C03359BAF317562776CF285F296B691D1B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028885Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:51.913{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BFA74C68972A3BB0D0BE5A26779E50F5,SHA256=5C21E0F61F0770F05B1AECF971C83172CDA873755B9EC1A234E68D851E483278,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028884Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:51.820{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=354D883742E9C2F9FB7F686076EEFE84,SHA256=FEF3F8453D743AC896CAD2A10A52E8F8081D0B19D71B0633A5DFC7B0B4258145,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041073Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:50.127{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58978-false10.0.1.12-8000- 23542300x800000000000000041074Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:53.113{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD25082D2C010D288B93AF0E242CB07F,SHA256=0821DA6E174146341DF4C46C996316F513689F88176176A4DD0BCD8D2B99E7E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028886Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:53.023{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E8F4A51ABC930C4A978B0706B38138E,SHA256=6A85770EF517C76ADC973AEB92171E7600EE20DDF5CE24E7F368E38E0DFAE21C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041075Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:54.129{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=56ADF37FECBB99036C3DA0288A27C09A,SHA256=E9B01837FAE85E6DA956F8E3AB6872EDE1492C8D6B708AE57AF6EEDDE6621369,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028887Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:54.038{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=635E160A6F9F46899564D88802855A22,SHA256=C898C47B7D9796C35AC500CEC040D6D86285E57DCDF4FD7DB8485226448C75B3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041076Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:55.176{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1756AFB2283CE3B3401892C53A8E8AE7,SHA256=662B8F6AC866E1BFD09BB632FDEEEB814EB6C0B282AEB5E1E1655DF2E8E5E169,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028888Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:55.040{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA18254A992A08E8A05F2820EB3C4FE3,SHA256=DC832A6B9D00E631FE937B5198E849CF2C37C55ADB41F5EF29C1E813B5EFFCE7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041077Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:56.191{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3ED0ED14ECAC329632204F0C1233BB05,SHA256=86A57A9004703C37F30C239D1376FAAE66898DFAA9CE4E86F39410FA0429D322,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028890Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:54.766{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51126-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028889Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:56.087{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F3DC78BF65F5C69A21DE6F3274C295D,SHA256=1149C189E6FBBAD06106678591D0CCCCABFAB6B7C54C8BD3A6C6CB07B98E4C0D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041078Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:57.426{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=921FA0BF31268D094F04129E47C5FF97,SHA256=9DA0F9097C3B3BB7E65FA4EC0AC6D7A15BB215520B6A797DEBBEDF5E60AD2AE6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028891Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:57.102{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E9EBCC5911A35AB58493EE00332730C0,SHA256=02C99651496C0DB021768C2F9D02142C8C343C94B8437F6B9C385469A9235E11,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041080Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:58.644{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F50635537F3BEBD159C9069767B720CA,SHA256=FC14AF5F2399493CCD18F4051843F62D4FFC584C925193DB2CDF892A192C20C3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028892Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:58.118{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=95AAD2276807A05C31473E92AC9BD19E,SHA256=F867009945A78466EE8466532020634F6D0ADF8F06F318257F95C3C70A79C344,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041079Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:56.034{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58979-false10.0.1.12-8000- 23542300x800000000000000041081Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:37:59.722{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B10D1C8DA5834993FC563DE7673AB107,SHA256=6AA5AF58A6FBEE5B8E213A6B3FFF2DF3A6FD23D26D9D290A987C2D560749CB80,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028893Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:37:59.133{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0BD8349A3AC33CEB900CFC64CD07692C,SHA256=82676FF61A29E4001B7CF6933F09B2FA74CFA42672C3064BB0382627BC545CE8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041082Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:00.738{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41BE92A7FB51813F0CDD16059F73C9EE,SHA256=AB14DB04B87865390F06F422564A7B5E00DD1CA81BEC9B9DFA56656297CB53F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028894Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:00.149{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA76CC9F924BEFC100E4B8A95F01D8FC,SHA256=A51A685E99D1ACAB047F125202887AD9DA565B39DC4216A8A295C07247505AEE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041083Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:01.754{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AAE55E15FAAB345007F7B810922F6BA0,SHA256=75789CE47E5BF74726CACEACEC948E8F280CE86ADB9060C5F2551A006D0D8BDF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028895Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:01.165{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2142358435205A5BD689B9E77AD62E67,SHA256=BBF74E870519BD56BAA2975C0F805797C1187775E63E1526C4315565837335E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041085Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:02.769{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=261F73B969B550B4497C3BD211E9E359,SHA256=4FDE9990F1137B1612CC845929BFD3B204B82B8CA0B7CB158C296D40C3A176F8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028897Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:00.766{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51127-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028896Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:02.180{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C36BC8C75D414C092F5ECAF1B9C56BA,SHA256=93BDA7EC8CA77D12C40D37F1157989AFA4F7CDB09FF937C096711395FA548C0A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041084Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:02.691{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=B3B29A93B652985F6A49E752AD6038EC,SHA256=314497AA23F98C49E55F3FD5F952DC58AC97276387F5D59781EEA9B5F74428D0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041087Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:03.785{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBB6E7CB06A0037C7ECC0151C13B17E5,SHA256=C452DB3292051B3FFCE0666BEABA257E97476F22223885CBEAA274AC2C6F4E26,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028898Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:03.196{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4722250CF8DEB7ECF91880BA7C4DFB00,SHA256=E72F8F05E01D4683F871EC1E86FAEB156EC50267ED0BADC653EA26078DD54C7E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041086Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:02.033{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58980-false10.0.1.12-8000- 23542300x800000000000000041088Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:04.801{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D8345CFB0685808B7FA5C791AC622FFB,SHA256=22D64AF8112FD21C80B11245BC1931670F8DB183CCE7207F09A17CF06591B504,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028899Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:04.211{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FCC2511559D9031F56AE77D353F1E898,SHA256=2E7B301EFF3154762B3221C68174294D6A35E55FE1CDB1B996713B9835F1625E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041089Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:05.816{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2A8513A3142389F03B8F8020E4F8364,SHA256=98215EAFB1CD84E5E6A9C451FD95D1B43CE5DC6610E2D760444FEB17CC17F94D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028900Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:05.227{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=65E6D409196A09CAE20F3FFBE6A025F3,SHA256=2E89E257C95E232B2E3F10F2BFD671C26D84E7528D3808F5C70F9DE44CDB00A5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041104Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.832{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC1B35B8CBCBA88B8B84A503C07D5E55,SHA256=973C29048EA957706F71F4C96CAE78C25EFABB2C26F194E2CE24E82734C0F8D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028901Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:06.243{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C011535A9F02F86A6A184D927958CEF,SHA256=D5C41CC3EC333F4EEB3506808C1947829A716EAFC955179B3D748E50860FA2CC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041103Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.519{8D4DD44E-78BE-616D-0609-000000000402}30404876C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041102Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78BE-616D-0609-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041101Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041100Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041099Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041098Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041097Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041096Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041095Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041094Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041093Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041092Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-78BE-616D-0609-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041091Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.332{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78BE-616D-0609-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041090Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:06.333{8D4DD44E-78BE-616D-0609-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028902Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:07.245{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B3CB651A889CC9838CB1862340316CFB,SHA256=9DAECBB7F452CB54DB87844C71AD570F1072CDE00B6CA4FA0217ED2FAE2FE96F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041133Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.710{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041132Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78BF-616D-0809-000000000402}5084C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041131Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041130Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041129Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041128Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041127Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041126Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041125Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041124Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041123Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041122Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-78BF-616D-0809-000000000402}5084C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041121Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.679{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78BF-616D-0809-000000000402}5084C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041120Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.680{8D4DD44E-78BF-616D-0809-000000000402}5084C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041119Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.351{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D119CB679C21FFADAD6806EE094146FF,SHA256=F0E494D14229075E2E7B67A4202EA4763D8F8B4FA1ECDC9C2C310CAEAA516ED3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041118Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.351{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3799F3DD1AA78FF3AEDE01B910D54866,SHA256=094682E9BD73BCE69798CCBF22E02EDFDE21225DB3CEFADC1C5DF6FA877E0147,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041117Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78BF-616D-0709-000000000402}4764C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041116Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041115Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041114Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041113Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041112Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041111Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041110Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041109Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041108Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041107Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-78BF-616D-0709-000000000402}4764C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041106Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.007{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78BF-616D-0709-000000000402}4764C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041105Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.008{8D4DD44E-78BF-616D-0709-000000000402}4764C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028904Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:08.339{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028903Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:08.261{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=23B17060BBC6B290CEDD67892BF4B16F,SHA256=A3B525BB15136BBCB1A85B34AE25ED76E9A32C5E26D6E54907020FA622651AEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041149Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.695{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D119CB679C21FFADAD6806EE094146FF,SHA256=F0E494D14229075E2E7B67A4202EA4763D8F8B4FA1ECDC9C2C310CAEAA516ED3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041148Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.632{8D4DD44E-78C0-616D-0909-000000000402}20364204C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041147Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78C0-616D-0909-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041146Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041145Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041144Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041143Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041142Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041141Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041140Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041139Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041138Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041137Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-78C0-616D-0909-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041136Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.460{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78C0-616D-0909-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041135Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.461{8D4DD44E-78C0-616D-0909-000000000402}2036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041134Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:08.054{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF5F75E9E2FA1FACF60E5BCD8AE0C363,SHA256=440D1079BD5846721AE043EC847F339BFFB67C83B75DE3A7B96EE10F28638366,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028906Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:09.277{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7369A3A01629650D62D47A71A0E98974,SHA256=AC05E389CA764D4ED142C586D25962AA22C0044D06995C779082ABBCBDBDA880,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041165Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.601{8D4DD44E-78C1-616D-0A09-000000000402}45202756C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 354300x800000000000000041164Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.553{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58981-false10.0.1.12-8089- 10341000x800000000000000041163Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78C1-616D-0A09-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041162Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041161Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041160Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041159Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041158Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041157Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041156Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041155Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041154Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041153Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78C1-616D-0A09-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041152Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.429{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78C1-616D-0A09-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041151Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.430{8D4DD44E-78C1-616D-0A09-000000000402}4520C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041150Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:09.085{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2367F16612D8D33E247CB80ABCFA0338,SHA256=065597D8230E009F8D8A4335FE7FD3A2E61A21C12D192F10FC63AB6817418BE2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028905Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:06.737{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51128-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000028908Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:07.878{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51129-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 23542300x800000000000000028907Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:10.292{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C25288B8EE8BC208C90B146B13006169,SHA256=8B469A1E7E4854AD8803BF89ABDD9D0CDBEBF029FE69A1342932D5096B8B33C3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041182Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:07.912{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58982-false10.0.1.12-8000- 23542300x800000000000000041181Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.445{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=646347BF78BD86D3A057416F498E3DCF,SHA256=4134F7C27DCDAAD7698B79CBD8EA394C96C5E7FE42863578AE873623CE1EF182,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041180Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.398{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE36FB5F807953D82CC4BFE78DAD8714,SHA256=A6229F9DDB223948FC9ADA2422530BFB72CD46D7166EAB65952C3FB956F9A22C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041179Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.273{8D4DD44E-78C2-616D-0B09-000000000402}49204032C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041178Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78C2-616D-0B09-000000000402}4920C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041177Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78C2-616D-0B09-000000000402}4920C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041176Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041175Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041174Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041173Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041172Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041171Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041170Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041169Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041168Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041167Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78C2-616D-0B09-000000000402}4920C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041166Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:10.101{8D4DD44E-78C2-616D-0B09-000000000402}4920C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041196Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78C3-616D-0C09-000000000402}952C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041195Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041194Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041193Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041192Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041191Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041190Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041189Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041188Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041187Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041186Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-78C3-616D-0C09-000000000402}952C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041185Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78C3-616D-0C09-000000000402}952C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041184Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.976{8D4DD44E-78C3-616D-0C09-000000000402}952C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041183Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:11.320{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16E592718EE92A32F8FC0FF1AF3CF812,SHA256=84A021CAE7EF7A7475D614CFA12C0E38D5461DD1B3A81D9B2D7195F33D2B11F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028909Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:11.292{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CDBE3881BC543159615BD9246DC934F4,SHA256=B34A6169C8478B2D6B5F6AE509D2DFC6F680305500670ACF8887EFF40D0D5990,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041198Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:12.991{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4D3D6E9980C06D1C18C9CFF4AAA03EFE,SHA256=61A519DF6C226F5110F94495A10BF7F1CA66924D05B9A396FF8BAFFBD0633D48,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041197Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:12.366{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2CC217ED82904EA6850AF161700A73D2,SHA256=4130121C83790CE44DC1736039903144103C85D5F40DE30C51CE33090DD0FF41,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028910Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:12.308{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CD8725FF9D4C3802496A7370094614B1,SHA256=A0B5E1E75425E4DDA5E2EBE8C8D0DE1531B5BE236F2A5FCADCE730B4E1AB6884,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041199Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:13.382{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4E0C4A96E31311E59ACD35116EC30795,SHA256=F57006F69C92505340003C4CC97CAB1F860AA1A3F470EED645004A0DAF5BA4B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028911Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:13.323{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3BF29901EEE7E1DC38E667B42D3D49D8,SHA256=02EDCDEB3B1BBEECDEF48F37D44B4D3FDE2D8D9249841EF2D63F0258C3A73491,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000028914Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:38:14.558{6F8252D3-5DBA-616D-1200-000000000502}288C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7c425-0x66a41745) 354300x800000000000000028913Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:11.800{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51130-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028912Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:14.339{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9443D1D5820AD0EB23D90863AC1377F5,SHA256=5449F4720B1D451DEE3840C10373E8CB69820CFB50F31337757FFB656B674A27,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041201Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:13.099{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58983-false10.0.1.12-8000- 23542300x800000000000000041200Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:14.413{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9783794EFE99767DFF58C0E9CC25F845,SHA256=3E940F200C7D69305E8425EB363EC1E582D86954788C509B5AB7420ECEB4A1D8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041202Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:15.444{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F54A2E81B6D3EC1227AFB02EC4C46EF3,SHA256=69EACC30270DE4BB70289A4AAF4858FC40320FF58BDBE708599A4D3B983860CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028915Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:15.355{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=710AE755605EEFCEFB13D0CFD0A2EEF3,SHA256=821A76882A8D50C85A2D00A4D814D60D9FF4BFE1753F58116E03B1EDAFDAC77F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041204Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:14.411{8D4DD44E-5BA9-616D-1000-000000000402}496C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudpfalsefalse10.0.1.14win-dc-185.attackrange.local123ntpfalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal123ntp 23542300x800000000000000041203Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:16.476{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1365928F1D10A08664D05EE2E28561E,SHA256=24A93641317F9D2CFDFA051AE9E9F968BBB9E450433AB5DFBD8174FD3D7BEAED,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028918Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:14.095{6F8252D3-5DBA-616D-1200-000000000502}288C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.15win-host-470.attackrange.local123ntpfalse20.101.57.9-123ntp 354300x800000000000000028917Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:14.095{6F8252D3-5DBA-616D-1200-000000000502}288C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.15win-host-470.attackrange.local123ntpfalse10.0.1.14ip-10-0-1-14.eu-central-1.compute.internal123ntp 23542300x800000000000000028916Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:16.370{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=62FA8344C07728A4169114A685951FC1,SHA256=4C2DEDADB2FCA55747E8A4E77A1647FC65D645B30069B3FDAA0FC84830885B9A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041205Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:17.523{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C999063C6C8D3F6DCFDA209F39BE5C58,SHA256=3335345F883B5B6BE6A65960BB3B1ED35752D4C7A5729A84D4257173405A69B3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028919Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:17.401{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3C43F11F3F70A1839896CFF2A6A37B0F,SHA256=2F6CF8B53F3E5C5866B27EA0775B2AC3E741EB7A0EF4EFD630097E24C23B99FB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028920Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:18.464{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5D9226DB7A32531742BD6FE0F5C78E5,SHA256=BBDB55497C51B37218F49FC360342DED3B0929B7EFBFE4B693195552666678A4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041206Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:18.538{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6956531C24EC26D203BCD7C728169CC7,SHA256=6A494E4032DA5689F0A8D330D0A7FFAB63F70B3150DA501381E737D5BEED6949,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028921Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:19.480{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=95056AE2093C5FD108F1A3EF9FAC151F,SHA256=C702220372D057121D2FDFCD965DA76429DB2FCA864651F76F4C56F406BA47C6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041207Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:19.694{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D7F326D096756E59C58E94A1F93A6E7,SHA256=BD8157155E0FAA37EC70871E9DE09D3010C0BC04B01DF28209DFF448E1E5B456,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041209Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:20.726{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=50701A2EA2B7A04665A48747CAA34764,SHA256=1EF681A49A95788F8F9E48F8CC96A38FDB665013D19D0EF94DCF9D5FD4A3D79A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028923Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:17.784{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51131-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028922Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:20.495{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8550BCE61D8E284E023D72D15203CF6B,SHA256=B515921551502D6FC9D5372118649B1FDBC0472DC8C08F9CA80CC847107A9EC9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041208Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:19.068{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58984-false10.0.1.12-8000- 23542300x800000000000000041210Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:21.757{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE6A40873FA343B34F376047740304CD,SHA256=0E69DF73AA246269D8C203E1023EE7945EB9D26734FACA6F4CE335B422ECB4A0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028924Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:21.495{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E450FB13768534CF8F053076A895B01,SHA256=ACE9A365B98E49CA27C6900AA3D94BC6741D633AFB75FFFEA3536F13C74593A5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028925Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:22.527{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39DEBE64AD80B4F86F2C601BC23C2AA0,SHA256=7A8A7CA8F1D600D97581AC25F942AADE802C56EE3952DE39FB6317CA31869EDD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041211Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:22.773{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=373F7611F3E1AD4A0E880B6ED6E43AAA,SHA256=F73229142CC78A15C1E96DC3CB8D9DD3E8872D439ACF9C6496A795E0C2DBD13E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028926Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:23.558{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3315D604FCEDA283A6D821B217382CB0,SHA256=E1E6F054B96103B9141F335C840E80D6EEA029833FEDA857121D40C25CFA0BF9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041213Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:23.838{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-120MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041212Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:23.805{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7556D170D3D3F4B0DA4746E76218E073,SHA256=C6B8DC326322236199B0AAD55B963CCA70A884DF9661F04FD505A0B2211E133E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028927Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:24.573{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=823EB6B8858B8FB894DDFA1F92A974A1,SHA256=CC01FB3A5663733F2AB44CD22EEBD50E5C9226182B62F41CF5FA4141D59E7F6B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041215Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:24.856{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3142572D74CA6CA48642A3D7A99F5C3F,SHA256=39C3CCA1B06BA710CB88A3B709BD107C63468A891BCB6AAB8209F2C45781E0CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041214Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:24.853{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-121MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028928Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:25.605{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C60AF2D9B6B09D524D9DD632EDF8D54A,SHA256=760DDFF0551D9833A68DEBCB6176E52B4BB2C2FFF4F287FC2789A19FD3BA30D7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041216Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:24.084{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58985-false10.0.1.12-8000- 23542300x800000000000000028930Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:26.636{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F8664C5D495C43655AE8FE8C013D595,SHA256=119B69350719DCDA7861B1285238032FBB44B6FC4840C8E2035A329D107C3EB8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000028929Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:23.721{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51132-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041217Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:26.041{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7E156092DBD63E61681EF2B632AF504E,SHA256=6D8F146C8091CE29BD354E797A18EBB8F4CF7ED150EE55FEA50AAF3E591D9C06,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028931Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:27.655{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4477F4DC0CD4633A4307402DBD3A76D9,SHA256=2307A6E580AE4C5AA1FAE9F075E7296FEA8607283461C59E80259A1164CFA2AF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041218Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:27.042{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08BD3128713B4FE6ECC0C232F5BF8FEA,SHA256=BC6EC9B2438730C1C6DFEE192A7D1D547588F5C822E7EFD87E10B080624E48E3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028932Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:28.655{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1E085CB8A9695557C56753D39AA3E0B,SHA256=5538398EBE78B7ED8983D8FA545935DF0C5FF916FE1BE2A0CFD3D9F545720BEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041219Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:28.058{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BEF1AE06FB8DD753B7AAAA57D329EA6,SHA256=4BA094C8BBD5FECC44560A45C777E8608673AF3FA3F56461CF998CCF0BE7F2F2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028933Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:29.687{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=827F622826D223D5F5245784254B8EC3,SHA256=C5135EAEA37AF22D82432C24B807FEBD261077CC5C27FACA11ECB99AC360EB65,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041220Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:29.073{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F7DF834882712C6F9C92B24924DA720,SHA256=68C8AC62563EF3F84C69E22C7B2992D4967E6897CB0DA5249D1A9CC5A83950D7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028934Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:30.702{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB81619EFE6512CD705660FDF677BA47,SHA256=E00859526A55FCB7382D5514382B7256D7BB4370860E2A4B7EF8EA1D08D7D611,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041223Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:28.011{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local56219- 354300x800000000000000041222Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:28.011{8D4DD44E-5BB9-616D-2600-000000000402}2852C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local63251- 23542300x800000000000000041221Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:30.089{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=402FF2B56DE6A34A8CB9C196A9F28DBD,SHA256=CB2562A168298590E7C9597F9E30520428A4F5532D38BC1077C249E58B287CEB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028962Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78D7-616D-CD06-000000000502}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028961Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028960Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028959Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028958Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028957Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028956Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028955Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028954Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028953Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-78D7-616D-CD06-000000000502}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028952Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028951Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.937{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78D7-616D-CD06-000000000502}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028950Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.938{6F8252D3-78D7-616D-CD06-000000000502}940C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000028949Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:28.772{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51133-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000028948Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.718{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C5D8A35A597BBD4876F0B77988EFD04,SHA256=6C8A6752C4C8108C1C79AED6B596A0446383C96B3563E228BFFBAAAB1A8345C9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041225Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:29.103{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58986-false10.0.1.12-8000- 23542300x800000000000000041224Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:31.105{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4AA4E4CBA944C866BD73424F8DC8EA8,SHA256=366358592CA88C7E7E88C197D079CC9730961886AB3AE5CF86751C01F48BFCFA,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028947Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78D7-616D-CC06-000000000502}2332C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028946Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028945Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028944Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028943Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028942Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028941Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028940Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028939Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028938Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028937Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-78D7-616D-CC06-000000000502}2332C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028936Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78D7-616D-CC06-000000000502}2332C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028935Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:31.437{6F8252D3-78D7-616D-CC06-000000000502}2332C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028979Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.859{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FBA71C7F9C8951278A19074B34EFD8C9,SHA256=3A359E9C7F7977D02F16F58BD9818BFAC01FE9A41ABB346DF6D8335E75F31CB1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028978Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.765{6F8252D3-78D8-616D-CE06-000000000502}38081000C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041226Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:32.120{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02917B5ED0B85891931BE24131E04AC4,SHA256=C73DDC0B5FCA9FD03028AD7C450F8CE7D3486308FDDF399B839A13299A9913B8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028977Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78D8-616D-CE06-000000000502}3808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028976Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028975Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028974Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028973Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028972Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028971Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028970Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028969Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028968Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028967Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-78D8-616D-CE06-000000000502}3808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028966Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.562{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78D8-616D-CE06-000000000502}3808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028965Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.563{6F8252D3-78D8-616D-CE06-000000000502}3808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028964Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.452{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5645BDD418F7094E4F0C2BBBD552924B,SHA256=62E5ABBEAF2F05E6C29B9AA71B04B1DB7AA6B74DD52BFD7BCEDB722AD36081D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000028963Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:32.452{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6E3BE5725AF81356EAFA08691E2EEEDA,SHA256=9E21609F7F505638FBC7AC97A1A2927E270DF688B4389CACD2AD8F29C44CDA7C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028995Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.796{6F8252D3-78D9-616D-CF06-000000000502}2680868C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028994Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.780{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2C22C0B6236EF40D84F82EDA19486ABB,SHA256=E4F42AAE189D8AE6B53572BD0E0D348A65607E3C3D6D6E3DF3970668D88838F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041229Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:33.136{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7BB2D7EDC1F9B60EAB74000733B7477D,SHA256=38272C82455526F3FD50C31D9F9AAC01366BA4473CB8AE6C0311364872A05766,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041228Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:33.136{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=309AD091821DC65958BDBAA5B4FDF732,SHA256=38579CFEB891F4602569ABE19EF1B04EB1D7DF2B7796FE6ED5CA08AD3C2FCB96,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041227Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:33.136{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7F8BEC5BE31C6AA161A3A68249CAAC15,SHA256=38BC29964752E98BC88353760354D5F99A4585EAD5C6644FBE130B2D9E00C05D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028993Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78D9-616D-CF06-000000000502}2680C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000028992Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5645BDD418F7094E4F0C2BBBD552924B,SHA256=62E5ABBEAF2F05E6C29B9AA71B04B1DB7AA6B74DD52BFD7BCEDB722AD36081D6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000028991Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028990Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028989Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028988Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028987Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028986Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028985Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028984Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-78D9-616D-CF06-000000000502}2680C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028983Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028982Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028981Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.577{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78D9-616D-CF06-000000000502}2680C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028980Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:33.578{6F8252D3-78D9-616D-CF06-000000000502}2680C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029010Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.796{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=081DE746113E4B5689A719A8C321BF05,SHA256=45EC1498C14F72F3C28A4905EC4E33DD1001BB9F76D89AE098231E81EFB1C549,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041232Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:34.151{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B9529A8D76D777959985A25CE7A63A36,SHA256=028D4F165D5BC77B5BC81141F566DD72FE72BFB23FA6B5CE8B923870CC31F8C3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029009Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78DA-616D-D006-000000000502}1940C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029008Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029007Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029006Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029005Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029004Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029003Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029002Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029001Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029000Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000028999Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-78DA-616D-D006-000000000502}1940C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000028998Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.702{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78DA-616D-D006-000000000502}1940C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000028997Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.703{6F8252D3-78DA-616D-D006-000000000502}1940C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000028996Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.593{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=16FB8C7DE91A84829CAF062DEAB0F751,SHA256=C79D784C5B27A4305CF67A6AA8D62DDF7174EDD2BD453BC7822FF4CF62FFD7CF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041231Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:31.947{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58987-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000041230Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:31.947{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local58987-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000029040Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.968{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7E7715F61D61984F0FD70A85EFE29ED,SHA256=E9AB2DCFDC7E4E468C5A69F20B4AE030C11927ED6F064599149645B3525570DC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029039Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.905{6F8252D3-78DB-616D-D206-000000000502}26921876C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041233Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:35.167{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=631CB3F85AD609B7EA5A0A707127C10B,SHA256=7DD109A7AA3307708974615C46612468A632F708270FC12A7EC43FFDB2BC87BC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029038Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.718{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A78AAB0556E01A9550483122CCD2732F,SHA256=2D0FF66CFC05B2273649F2F16F931E7C6887BD9B54B527954A8066B32A4E14D3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029037Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78DB-616D-D206-000000000502}2692C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029036Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029035Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029034Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029033Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029032Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029031Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029030Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029029Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029028Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029027Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-78DB-616D-D206-000000000502}2692C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029026Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.702{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78DB-616D-D206-000000000502}2692C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029025Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.703{6F8252D3-78DB-616D-D206-000000000502}2692C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000029024Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.468{6F8252D3-78DB-616D-D106-000000000502}24042240C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029023Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-78DB-616D-D106-000000000502}2404C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029022Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029021Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029020Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029019Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029018Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029017Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029016Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029015Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029014Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029013Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-78DB-616D-D106-000000000502}2404C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029012Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.202{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-78DB-616D-D106-000000000502}2404C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029011Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:35.203{6F8252D3-78DB-616D-D106-000000000502}2404C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029041Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:36.937{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1AB9E385D86924FDFBF4E6632561A55B,SHA256=9E285D7AAC0E180359A9791321E67DF332C9DFA04491A087FDC6BE1C680729CC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041235Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:36.167{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B635AFFC07DE8B3591EA81895A999A7B,SHA256=8F0AED65DFEBEE61769254A13B9FEBDF5DA470F0ACA848822F8E70AFBCF55152,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041234Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:34.884{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58988-false10.0.1.12-8000- 23542300x800000000000000029042Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:37.937{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DAF404BA4F01B456B295308657E15DAD,SHA256=C284BBE3A0301544940334DA260E94AC6652E84F4FA0E652FB6C68E9BF0DA423,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041236Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:37.183{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=518630AB172EE332EEDF4439BF07E491,SHA256=1BA9C65E5977EDBAD5F23CED74A1F120F88F78B9C8A442A06B1918D026134297,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029044Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:38.968{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE420395BD3F6963A86A866299C68F49,SHA256=1FB8A6904E67026AAB683E777745F478C9C63DDA6598507F3C79FFBA329B306B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029043Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:34.631{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51134-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041237Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:38.198{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1FC423EA22CF45A916A24EC4CA9DA84C,SHA256=37F74782CE4D2C1A42DC31950E37B83E11305BB1DF37610517C6B9AFBC25895C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029045Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:39.984{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=86D2749ED74F823D8638D73BDBC20DAD,SHA256=15059E5AFB88AC21D2FC5D5A24C68DF1F10FBEB4A97682CD6772B61045B7959B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041238Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:39.214{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D3F5F9166029C18B6C650AB00C180A9,SHA256=C711FD2BB9E88FB324C3EA4BEB1593E01B62D4D11E83C9412936B97CBC3208B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041239Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:40.230{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDD6940A6CA424247F0CFEE40186444C,SHA256=6CA49335E7406F4FC6DE74E05FF8B0719FD5B22102A46E25B75CB82CB18FD10D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041241Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:39.916{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58989-false10.0.1.12-8000- 23542300x800000000000000041240Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:41.245{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C1416CA26227667CEBD48600AB7BB427,SHA256=94FE0292783EE13DFB755ED22EF36FEC5EA425AE8E76EAA364279FDEE896622E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029046Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:41.015{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC9E4C5F860A66FA18A8E3AFA3BF3109,SHA256=53CB3D832783274A01109B83D290006726DF1D3FFB38950CFDE7243EE77C5981,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029048Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:39.678{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51135-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029047Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:42.046{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C600713FCB1CD3EAAD5033A5C000663,SHA256=C813FFEDB57F07E4D771FA55D8F3587C1D0D98DC6C5F3430FB29D79FA77CA810,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041242Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:42.261{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A4A1A0289FA19F3C677693F9EAEF6CD,SHA256=22668C9797A709B551D6361E4E5EED104E0973DB297806D262198B28ACE84C11,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029049Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:43.124{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F7405DFF4C7787C3E4EBB368F7917C6,SHA256=ED3E54F90E801DF9B806615F32C20EC5112DC0116BEAD771D75D056E33E0E2CE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041245Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:41.542{8D4DD44E-5BA4-616D-0100-000000000402}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58990-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local445microsoft-ds 354300x800000000000000041244Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:41.542{8D4DD44E-5BA4-616D-0100-000000000402}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local58990-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local445microsoft-ds 23542300x800000000000000041243Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:43.276{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BA77F9EC354D15E00C5B3812B9FD15D,SHA256=AED0522C3B85CF3B307CB22D7D0BBB537DF69F329B7AF7097F8BC227D7136E7A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041246Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:44.292{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37187BDE43548F6F0F0FBAA288843512,SHA256=B29BC5DA62EE229BAF245028A6B8D0BD991AD4B6E408108CE5B1A38249E1C7C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029050Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:44.140{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=025153914076F5131803AFB95958F9D9,SHA256=8CF033814E72A3152646A03C730AB629EF027034420B3E4D66CBE554D157B018,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041247Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:45.292{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AE1A5F7B0C7BF929E7A1C2745ADDA46D,SHA256=663DA73B0D37231D456C2A6BCA0A65940549DC8968501D9315D6E5B5F3B9F9F0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029052Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:45.548{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-112MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029051Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:45.171{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C03CAB70A61CCADC07901580B1969E5F,SHA256=AA5DE4BD48BCC010CE34669A3D4B06983815155BFBCEC8CC2136A19562C4CC99,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029055Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:46.563{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-113MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029054Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:44.804{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51136-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029053Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:46.172{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9D24C06E783BBDAC42EB277DE266A58,SHA256=97D8F540695BEB809D9D990F37669E3D1815FECCEF80B275EB011252C92FFA9D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041248Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:46.308{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=127BCBF28B4AF8BC86F54FF45B5F2D29,SHA256=0A92A8250087030F06B10E13A3C7D6311E5327A92597464429C95A3BE7C617EA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029056Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:47.189{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A2C5E443710EFFE158DD1088A1AFE346,SHA256=F135DFFABFE543551C664D6035637AD7CCE7C1D2A391E766ADF5DE2003CBC03E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041250Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:45.931{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58991-false10.0.1.12-8000- 23542300x800000000000000041249Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:47.323{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0F41281703EFB5ABCEC3589656D08ED6,SHA256=E5D11266F3AFFBC3BE89D624EFB9CDA29D60E82280E9445523D7CEBBE7BBE33B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029057Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:48.251{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76E1D54EC8FE3686FA620C44CEE21D27,SHA256=88BD382E0C7F4B91E662E5326486EEA7229EF85AC04A693E2B9C48D4D1F3BBDE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041251Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:48.432{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5ACEBBFEECF64693AD7B59AA74422A81,SHA256=6B748CB41F30FD2D0E124A001C9BD075D80D992F80EF7776E0759DE3D0D551EF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041252Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:49.667{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=771ABCE43D052F42A23BBC34CF6B74B4,SHA256=9BA091F55693FF1BE31AB783B60B687A6F7CBDBB6478FBCE6054AA9C45CFD577,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029058Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:49.298{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B93A9174593DC41BFEFFECBB851E95EB,SHA256=1E98F853EE4A02947DE14D83E1FF933222D0B3BC33CB843B4E0615387F7725A7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041253Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:50.682{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44A50F12C8A06BC249436665DF6B41DC,SHA256=ACC3A9301366E66DD7F3F8ECEA9F07E73F583EE8E78AA8027B1E390A853F785F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029059Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:50.329{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=409CE5943B40289E95EAF9DE054A5B5B,SHA256=DA0B88D4BD5EE1534A7DA7C8D904A58CC58D12EE9846A15FADED671B45105FDF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041254Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:51.698{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AA735599870D7DCD809DEBF359452463,SHA256=14411F23D9C588303C3D85CE8C0D27AA7356D7DDC439574BCAD6A2C03B1A810F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029061Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:51.829{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=EC8B731924606C4722D81FFB67F3B22F,SHA256=581958E8BA4120B1B7E268EB3C8CD7E374A20F79288F279B5B14F0568B08A578,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029060Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:51.345{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=558598FE174931CE01442B47079AE23B,SHA256=965E933555D7F3BDD826F1522E9038E6A3AE28F87DAC61E1EB185C7478AF10D2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041255Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:52.948{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9498128A1636B0D3ED061938B71D77D4,SHA256=A9887018D224410AEBD33906147AE819D827274B89103CC2A94C1ECA3691C252,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029063Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:50.648{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51137-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029062Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:52.361{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4305F03B57A0F3EC0DB09DFB531D74DA,SHA256=C7733743672C29605F9C577C067C5C7EDC820C0AF2B59121404ED88E521BEB00,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041257Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:53.964{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21DBE63981ED720F43C3127DD38C64A7,SHA256=69A086731FC7F20AFAA2B41EC0B3F09422308AD027BCB96C0FCD389C4A90B0C1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029064Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:53.376{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0527BC9D415FB3FBB13E847958233F62,SHA256=0FB8B9F732F6094DFDD629BEEDC7582E55D73B6A8C31FE445F29CEE60AEA3796,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041256Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:51.118{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58992-false10.0.1.12-8000- 23542300x800000000000000029065Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:54.376{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1877EAF362D21D326E61992F2543F5F1,SHA256=86F111761C6536013A19A23944CDD0DA731466DB34F024C2B0A6F93D88C48693,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029066Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:55.392{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED56C93315885AC8885FBE70C3C37FB3,SHA256=3924464F8E1E91B1FBE2683FEC421B0985ADE5786EDFA14F3C41EA0D28040B5F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041258Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:55.042{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4093A89BA26EEFA20BFE84E72F7EC172,SHA256=BD268F1BD051F1BCF10560B220CFEBD95F40E618F8E24DC36536BDAFEAED502C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029067Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:56.439{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6C7AD7E95A3019F379D8E3E3ABDD995A,SHA256=1EA98D1FAC606BB96E732CCAAE962A3AC4DF2FCB02AA9AAB6251AC25229F17FA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041259Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:56.073{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02BDF407885AC13B5D8F5674A21B5139,SHA256=04939A8E11972610CC4B76ED50D98ABAF547A320706847A589A3C16B28C52DC1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029069Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:55.663{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51138-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029068Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:57.454{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=66BAAC93FA829B1FEFBFC16320F5890F,SHA256=EA5982866D09401B1F64594737185682D09411D0ACA215067752461456435394,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041260Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:57.104{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EB5CCDFB9746D88EB70AFBA875EEBC7,SHA256=313F62DDB68D9FFD24496C52575819475C1384E6D1D2FD1FE5AE3AF5292D6203,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029070Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:58.470{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EB2A1010A56E5278D599D54EE8E7A18A,SHA256=60C42624B121B94C3E5887D2E5AFFDF5A1C1B3CC7FE918C7053A9045FF631D43,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041261Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:58.167{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E5381D0CD8246931124F2EF6F57353C,SHA256=9193293E565E133DEABF02685223ED13FEB8F448286A7560BAE9EF595179A6BA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029071Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:38:59.517{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=312A7FEB276E8032870ED02C80A28371,SHA256=42827DD7984829E847A4A57BDB86132D387449DBEB50D0D62070E6CB92BA2DDE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041263Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:59.182{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=82FDF38149701A711F45B9F67E0A209D,SHA256=FC71C2EECF2F25FCACE65C2744302149E01F54C0963C701C7B71454D3E124A9F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041262Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:38:57.055{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58993-false10.0.1.12-8000- 23542300x800000000000000029072Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:00.548{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=14CC8B221AD6745C975442940F878C24,SHA256=2C6E540E8C5A73827E03C0C743CF3734ECC9A0757C5FCB5B437FE4065A355C7B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041264Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:00.417{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05A01094000E55CEE40DCCDB6F896725,SHA256=4F552D51F587EF41DDF97B848036EC48A122A71170485831F297A041D99DA040,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029073Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:01.548{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=75568C275831A7B4D0455F507151411A,SHA256=F8E52C2FFA76667B19A738B4524AB122B01EF67A008CBA504CEFB4C37C01D00A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041265Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:01.448{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FAB6C1C3A4D67C947F94CE84747F852E,SHA256=3DA1EE21FA0D79DC87B87AE9C4E3138438F30CB0D1BCEBF99964263ADA693C42,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041267Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:02.698{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=FAE943E7FB7F9D56A2C9EC22717F520A,SHA256=1BAC08F2D104591F7CBA62750DAD0B676A8D464BE7F2F90B6479CE6B9CEDAD3D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041266Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:02.510{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EEBE17EF2D18535F68B4ABEECD92D83,SHA256=5184BD640ECD13D3D685C10AA790313BF6FAD5E204B214209C7A8903666F3002,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029074Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:02.579{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=009BAAF29BE0F77DCF4D635332C6F2AE,SHA256=5850FB17736257874412908623984648B6798084020A58E507101088CCE67F41,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029075Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:03.642{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEE0DDB833A8DF29E2B924B2FC54675F,SHA256=BB8AD56275CCC1B211B9F27BAB5569B1437BDF26209929D5DF0CA49301040A0C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041268Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:03.526{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0282FCCF99B2BDEE3731A40EB8D40151,SHA256=8EACA8216210F03496ABCB222736351F183CC7ADA42CB287193841C60F9B0E52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029077Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:04.673{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE6ED34083D849555796EB6FA4E854C6,SHA256=354D6D007BE45B9F3FF91E3A9B001013E0DBD438FE85E06C84A75B2B343EC81B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041269Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:04.573{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67E346F172C12F0F0E26FDEF94C53E94,SHA256=10F9AA8B1ABDA2B5F519F12D9FDE1826D3F55E88268BBD654BDCE8994BA0744D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029076Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:01.695{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51139-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029078Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:05.704{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9AD882D132AFAD3CC2B8D549693816D2,SHA256=00976D18671CDFF527BD0F32EA48FBBBF95B80F549DA15C9C10E878082ABA12F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041271Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:05.604{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B921BE0B3CB70DEFF80F151F0BD772A,SHA256=3DBFE471E23C27A4A9646AE6AB25700919CD9BC9A82427639A53A021CE0CAF3F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041270Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:03.102{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58994-false10.0.1.12-8000- 23542300x800000000000000029079Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:06.767{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE7207B8C094EA43F82BEEE517D36EB5,SHA256=B811BAFFB0BF6676D06380430A01014C88004E0D5F905644BC466FD28BAAC093,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041298Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FA-616D-0E09-000000000402}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041297Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041296Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041295Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041294Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041293Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041292Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041291Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041290Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041289Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041288Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78FA-616D-0E09-000000000402}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041287Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.838{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FA-616D-0E09-000000000402}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041286Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.839{8D4DD44E-78FA-616D-0E09-000000000402}1920C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041285Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.651{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2D5F588F246F4F6EC1CB3FBABF3D9F17,SHA256=70BBA54071A5B1D3BB158338A5EB6D6730D71E6B5141E9927140D76CB243D883,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041284Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FA-616D-0D09-000000000402}4640C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041283Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041282Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041281Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041280Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041279Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041278Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041277Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041276Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041275Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041274Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78FA-616D-0D09-000000000402}4640C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041273Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.338{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FA-616D-0D09-000000000402}4640C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041272Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:06.339{8D4DD44E-78FA-616D-0D09-000000000402}4640C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029080Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:07.816{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5AE2BD20D1296A74D032A214D1A7FEF,SHA256=F68A9C737AF6704295E5EB395E31E86498A543F7FF62894B0BEDACC628CB30CD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041316Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.733{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041315Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.671{8D4DD44E-78FB-616D-0F09-000000000402}47004564C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041314Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.671{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=74617D90577D8EF02D9B3E7034AA4600,SHA256=8D80F5A15B57E4F3420EC375900507B9B5D5DD95BCCD64A3B634E0892B983DFB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041313Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FB-616D-0F09-000000000402}4700C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041312Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041311Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041310Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041309Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041308Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041307Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041306Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041305Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041304Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041303Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78FB-616D-0F09-000000000402}4700C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041302Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.499{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FB-616D-0F09-000000000402}4700C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041301Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.500{8D4DD44E-78FB-616D-0F09-000000000402}4700C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041300Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.343{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CEDBBA99BD84598384900A895A621172,SHA256=4CE19E4EB0FD42ADB777FE909E76139E9D86156F93050880AF0019887C315587,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041299Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.343{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7BB2D7EDC1F9B60EAB74000733B7477D,SHA256=38272C82455526F3FD50C31D9F9AAC01366BA4473CB8AE6C0311364872A05766,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029082Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:08.831{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C1FC91DCC833E672E970485DD154446B,SHA256=04C092E0DEC08B2687ADDAEA820D92AEF138F2EFCCC753BD3DD99B638D66E335,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041332Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.718{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B71F3090520A5084B1F4ECFBF71EC06,SHA256=6CD4201CECD367A6B428D5D358B80FBD988CC62E23446E2B6E6CD0CA143516F6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029081Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:08.363{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041331Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.625{8D4DD44E-78FC-616D-1009-000000000402}4001060C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041330Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.531{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CEDBBA99BD84598384900A895A621172,SHA256=4CE19E4EB0FD42ADB777FE909E76139E9D86156F93050880AF0019887C315587,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041329Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FC-616D-1009-000000000402}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041328Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041327Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041326Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041325Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041324Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041323Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041322Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041321Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041320Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041319Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78FC-616D-1009-000000000402}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041318Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.452{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FC-616D-1009-000000000402}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041317Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:08.453{8D4DD44E-78FC-616D-1009-000000000402}400C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029083Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:09.910{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE42944F87046C2D32B76C0C41468BE1,SHA256=1B1FD9643B5BEFA5B0F40E0ACD76D1B23015A3E9BE9815BCE51BD2658D2FC1B0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041361Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FD-616D-1209-000000000402}2352C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041360Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041359Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041358Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041357Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041356Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041355Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041354Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041353Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041352Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041351Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78FD-616D-1209-000000000402}2352C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041350Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.952{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FD-616D-1209-000000000402}2352C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041349Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.954{8D4DD44E-78FD-616D-1209-000000000402}2352C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041348Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.733{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1DA594A1E441A8138231D88CB38E26C0,SHA256=C65BE971B055B387DDAAB39850DAC1590A149DA09465637EABE76DFBF176FCE8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041347Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.577{8D4DD44E-78FD-616D-1109-000000000402}3424388C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 354300x800000000000000041346Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:07.591{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58995-false10.0.1.12-8089- 10341000x800000000000000041345Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FD-616D-1109-000000000402}3424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041344Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041343Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041342Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041341Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041340Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041339Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041338Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041337Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041336Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-78FD-616D-1109-000000000402}3424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041335Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041334Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.421{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FD-616D-1109-000000000402}3424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041333Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.422{8D4DD44E-78FD-616D-1109-000000000402}3424C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029086Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:10.941{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AA88907FC3D2F644FFCE714D6A063DF6,SHA256=FE91E9CE575E559067D7CA77D7DD848A29810FB113719D87919BCBAF554B12C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041365Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:10.765{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=033A94F4F95E78D910E379349DCEA6D3,SHA256=EA9BBCDBA8CA64EDA9B08536CCD17C32E9E21C0355624C4FBB4619187658775F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029085Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:07.900{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51141-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000029084Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:07.712{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51140-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000041364Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:09.060{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58996-false10.0.1.12-8000- 23542300x800000000000000041363Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:10.436{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=768EC9B09B7566F45A8C2EBA94923710,SHA256=8AEF59B6C0E9295685E99A698B3A139BDCB31C425EB381A1C3BBE0187533DEE6,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041362Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:10.108{8D4DD44E-78FD-616D-1209-000000000402}23524132C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041379Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-78FF-616D-1309-000000000402}1664C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041378Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041377Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041376Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041375Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041374Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041373Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041372Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041371Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041370Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041369Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-78FF-616D-1309-000000000402}1664C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041368Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.936{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-78FF-616D-1309-000000000402}1664C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041367Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.937{8D4DD44E-78FF-616D-1309-000000000402}1664C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041366Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:11.796{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=14C74E7E30E353410A7223637FCB100C,SHA256=3D425F52C068981C3A40AE369BE1F41C98C2C632860DC4C1689657DD7166CDF0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041381Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:12.952{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7538E761DA306C06F224ED567911227B,SHA256=ABE395304479095929DCB3B58C99B9075587B5AD36EE560DE5791B140372C340,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041380Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:12.811{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB86164F03D17772218B9D4AD6269C4E,SHA256=E6B55A2844571D485DCB599836C2ED6B22ECF5CED51ACD2F4E9F0D2B63BF24C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029087Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:12.003{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=114C1D7D954714EA2825C1B5F4813CAB,SHA256=8D097EF1B116B8BDA1F3C596D7C9CBEFCB70B77694ED28564060FFEA7A2A3973,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041382Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:13.952{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=854A06AF78A72ADC38E575A4702E7B33,SHA256=E26ED66586901A428BCDDDA9EDFDEED91B374BBDBD883B9C132FCEF6882472BB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029088Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:13.050{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F1CDC845E3988609D19DF231089BD584,SHA256=954B572D7751377CCFBD6315C59320712EE02CD6740BBC2AC8D4E37936B5048E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041383Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:14.968{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ABF7A6625D9616A66E5911DF932E3918,SHA256=B647DE83C4B1713DD943C1CC25CC6F6F202EB4745BEA9DA9A62D5F6EF1011597,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029089Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:14.097{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=79EC98AF61EBAE2FD99B278B294279B5,SHA256=C22DC3851CB69EA1556CB9A2A1E47D0DB250B1C6EDA8345385CFACF7B45C16A0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029091Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:13.634{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51142-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029090Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:15.113{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A9D838E19678759B6AB8E9F51914B80D,SHA256=ABDD429E25085FF6D96D3F23B19A634D9F11F60D171711BE6E20D6D9B4B4C7E9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041385Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:14.919{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58997-false10.0.1.12-8000- 23542300x800000000000000041384Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:16.186{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=37F7272DC49CCDC19D6E3FC9E2DF626F,SHA256=3FD26E27F87D48B231ABD78536BFEE5EF59D9814AA2A85B2F389F7CBEF0D2AC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029092Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:16.144{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=061E371B95687C7CF57F79015B1D74E1,SHA256=0CC3522AC9B86AA14EA4DE10A4C736AB5333ED297E192AE5E5B5B078D35DFBB3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041386Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:17.421{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D34D973F5150A7006D262FBE377EC2D,SHA256=9D24C39336E515BD9908306937446A7FD704CAB3951B474DB171DFC49D650C9F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029093Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:17.175{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E11F2E47ADD041A103E9BFCE677322A,SHA256=C968CE21ABFF7AC5A52A5CBB1C94D049BF6093B647FC90F2A174E77A16FA3EAE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041387Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:18.655{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED2D9C71D9A0D1AA5A8EF38216EA6DB7,SHA256=772FFD648D495FE497DDB0D2A439406A48ADF2F1B8C02197771CA2494B2D53A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029094Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:18.191{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A67FD9F548EBF3B67AB5A1912C402741,SHA256=8FF569F1DFC37E19B18D94356EDC86796FB26F5AB96DAB287657F5E016A6AC2E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041388Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:19.655{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE98BC161482F014A2DB65C4E905EA58,SHA256=330F25D373814D79FAA233E457D3C216919C68EFF2B328CC96C0569BF7E791D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029095Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:19.269{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76B3E52E750C04F88C1D53ECE17D5419,SHA256=3BE47BE9F9CE129D45A9811EF0A7F5F458829277FF45087C86EA5BE23C47B9C6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041389Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:20.672{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18B3B2BA46370DA516C4B0BAD7BD8F6A,SHA256=063F6E52F69758FE4B9CD41B31FE62D53C488FFDAC8A8158C6E0836B89E2F43B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029097Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:18.743{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51143-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029096Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:20.285{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E1E26F39D023A53CD018DA20CF01ED15,SHA256=72CBE63CA632D34B2C6E990CEE372BEA243CCDDEEF1D0F0FE58110DCD6D7A95E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041390Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:21.719{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=419276BF4F36CD06E4A712AD482B3953,SHA256=696D5E095CB52CFC073B23AC35F2FCA22EAFDF830052446381AF715FBB118264,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029098Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:21.300{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C51EB1CB55328FA7D3B7E954D0E10574,SHA256=07C6FD65B22D8C53382852C7FE30C7AE6265D28751DC3DB529A3597C5E8717D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041391Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:22.766{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3BE4A11D7533F23D895F0D5ED371048D,SHA256=9DDC1E656E008C794097B009C75F0B2D149F356647FE5B4BC8F8A7CE6F08C83E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029099Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:22.316{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D131B9AAE230680A9FB7CA483F6BEEEC,SHA256=A0AB7FB978FE9CFC6257E00B2B401A0FCCC063ED665FB55802975F92BC8E03B2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041393Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:23.781{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7A33871C8027DCFFEC681E445E7F34E3,SHA256=A30C1FCA8D6F061B11BC127151290DB6D34A2E4C9C11DEB2F3FBD5E0DC9AB47C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029100Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:23.347{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=900AB36F39E03389F565547E7152F4CC,SHA256=5687D528E2A637EDD2C7C780F494C859144E0C8B2EA2E6206590F523956FD338,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041392Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:20.905{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58998-false10.0.1.12-8000- 23542300x800000000000000041394Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:24.797{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5B90BCF826B1CE2CDD625C7546B5AD7,SHA256=4970F7ED9B655626F69B5D8F137B10640E38D778F0B4106C7DA4040E149760B1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029101Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:24.363{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8E591BD2539B508BA54829311C8230CC,SHA256=5F4E633F29A66EE1DCA4F90A8270C19C4C438E41B0A48A93078F556DF71E0776,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041396Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:25.798{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A9F7552AC8CF50372F3CA73B026CA9A3,SHA256=453D7CD272E9E8DB9A850C25B1C9E659FADAB5621E94B9557E6E7BFB3C272165,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029102Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:25.378{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7BC4092063D48D6690677843468F4E1E,SHA256=6668FCB45678194F3CB7B6939146B6C98E82C76F83F0EDCF2D1C1952BF633CE1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041395Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:25.378{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-121MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041398Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:26.812{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CCC39E4D06D3DA7FF5528F7E78DF608D,SHA256=B003854ECBE27A3B6BB172D17C8CCE7C150941B898015EA85E2F902183FC59F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029103Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:26.441{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4B9CD0BD2C7331B2F37822350FEF2C01,SHA256=9618408738CDF27761FFB59C4850B742A4A5CB9B954A370D740B5D853495419E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041397Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:26.377{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-122MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041399Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:27.825{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7ABA5992877B4AF38558A4F98CA78FDF,SHA256=DEF6E1C9F309F1F6CFD7A8925B94EB19237BB13BFAA65E2448B436F8EEB0EDA1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029105Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:27.485{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F39DC17402E5AAAA6BF02B1D223AF124,SHA256=1E43C68DC72CA6000ACF17FFC12B3FCABB06B05C5500E20E9540711B5457A6F1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029104Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:24.774{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51144-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041401Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:28.840{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=07FB4D5C359783690AC575A6C64504E5,SHA256=449ADBEC34DED9F6F26CB94C1B5897018BE5274211C04F7739C5C6DC0A064B29,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029106Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:28.501{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=702B637BF3C08A5BB0F2BC52897E978C,SHA256=B1CA6D5A56D6046473F443239BDA2161F21C8E2072BDC1B4457F27ADB26603C7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041400Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:26.093{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local58999-false10.0.1.12-8000- 23542300x800000000000000041402Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:29.856{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A739C776FDEE75DEC92868EF9490AB93,SHA256=FE82E6DC2964C2E061892A251B689A651B7844C0DB0F0E1EB9136D58EBAF7B70,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029107Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:29.532{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=60956B46EF0D134375F0FF7E9CC149A5,SHA256=09ADA32BB33843D4B02DA918062D6441465562FDA315211DD2B43D2BA52C8E5D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041403Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:30.871{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD1AAF2B3A1074A9E466364EEA4B2644,SHA256=9DDB4A4B0BE88D664739AE0962AA154D37387456E968BD31A7091F2ED0DF3DC5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029108Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:30.548{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=081EB5ACE047CBC804538545A359EFCA,SHA256=C7585CAE707E4FB9E90D727847316D792A9AC4ECBC0824B27D65089BEC46936D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041404Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:31.887{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6127A17340B322C2D3ADC56E46BFE894,SHA256=B3D9B0F270D2E10E25F7A1E14D24818105EAC131230BF1D2194AD41E65455423,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029135Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7913-616D-D406-000000000502}2636C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029134Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029133Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029132Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029131Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029130Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029129Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029128Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029127Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029126Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029125Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7913-616D-D406-000000000502}2636C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029124Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7913-616D-D406-000000000502}2636C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029123Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.970{6F8252D3-7913-616D-D406-000000000502}2636C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029122Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.563{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=402EE8216201CFC57F7E5C88043C523F,SHA256=135F6AB0E16F53D73D18B1E4FFB543EF7DF4D0AEF9225746C49EEE46CF4B5029,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029121Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7913-616D-D306-000000000502}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029120Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029119Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029118Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029117Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029116Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029115Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029114Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029113Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029112Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029111Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7913-616D-D306-000000000502}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029110Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.454{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7913-616D-D306-000000000502}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029109Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:31.455{6F8252D3-7913-616D-D306-000000000502}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041405Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:32.903{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EFCF705BD0F0FF7DD7F2E3D9AE52EA0A,SHA256=0ED5230C8A5E1EC8E98C2AF9EFDD8FC0B0C3E5584F1F8999DB3017AAC8C820CC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029152Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=465380DEAEF8A0098D8CCFE1B5565354,SHA256=A1BC476F8D654277F59B8F28DCA849A41973DA0AA3FA28CE87CC0B6CDFA70385,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029151Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7914-616D-D506-000000000502}3392C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029150Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029149Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029148Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029147Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029146Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029145Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029144Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029143Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029142Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029141Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7914-616D-D506-000000000502}3392C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029140Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.595{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7914-616D-D506-000000000502}3392C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029139Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.596{6F8252D3-7914-616D-D506-000000000502}3392C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029138Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.501{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0DC563B995AB2C23A4B144268A27CEF4,SHA256=558A6B3F349EFA4C5347B138DE4711B68BD404EC3819853EB9C810A54E734152,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029137Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.501{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C5DA2509A47B8FB7E473D63190A21B86,SHA256=686A6B3167F4EE78E6CAB3ED58706598216415E57148CB2B0B6101ECC8BB0CD0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029136Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:32.126{6F8252D3-7913-616D-D406-000000000502}26364044C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029169Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.829{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08AA63BF4E46868E688DD1CEB988BCB2,SHA256=DA82764BD70EABE7D0E7ACCFF71AF5F93821BF6A4E41DBE61875334D0BBF6A63,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029168Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.829{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0DC563B995AB2C23A4B144268A27CEF4,SHA256=558A6B3F349EFA4C5347B138DE4711B68BD404EC3819853EB9C810A54E734152,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029167Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.704{6F8252D3-7915-616D-D606-000000000502}25283936C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041414Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:33.903{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F2101C542316C12AA812624CC030A1F7,SHA256=AD1BA5AF7B36FFC50342172604DA83B1FA423E8014490AA4E38F3410CADF5A7F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041413Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:32.073{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59001-false10.0.1.12-8000- 354300x800000000000000041412Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:31.963{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local59000-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000041411Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:31.963{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local59000-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000041410Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:33.184{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A93BE1F75C626838691064915B9348DF,SHA256=48F49484671A614506970B62A47FA26E295EC4893907491A3F76A4381C185A6D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041409Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:33.184{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7A0FA3A3F8643FA0478A0B210DD0E7EA,SHA256=3051D9DB5DDA50713E322297B347C4D8FA3D34760416826F2558937EE531F82C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041408Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:33.106{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1500-000000000402}1248C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041407Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:33.106{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1500-000000000402}1248C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041406Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:33.106{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1500-000000000402}1248C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029166Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7915-616D-D606-000000000502}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029165Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029164Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029163Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029162Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029161Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029160Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029159Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029158Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-7915-616D-D606-000000000502}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029157Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029156Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029155Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.532{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7915-616D-D606-000000000502}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029154Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:33.533{6F8252D3-7915-616D-D606-000000000502}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000029153Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:30.662{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51145-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000029184Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.970{6F8252D3-7916-616D-D706-000000000502}36323804C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029183Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7916-616D-D706-000000000502}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029182Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D925CF56871E8F660D5A414803F64BA6,SHA256=62136DBC7FA79B5467D6E1D657DEA4D1A93066E0E14ED9E5F16E897AE5E85BEC,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029181Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029180Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029179Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029178Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029177Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029176Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041430Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029175Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041429Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029174Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029173Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041428Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041427Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029172Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7916-616D-D706-000000000502}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041426Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041425Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041424Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029171Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7916-616D-D706-000000000502}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041423Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029170Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:34.720{6F8252D3-7916-616D-D706-000000000502}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041422Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041421Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041420Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041419Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041418Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041417Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041416Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.965{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041415Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.918{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=460F190525257B2E340789B0194D5F42,SHA256=2B4FDB747C13BD9F8FD2DA593780AAFA626A773DB4B9AE39D4C0DD4A1B75AC00,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029212Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.907{6F8252D3-7917-616D-D906-000000000502}30123124C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029211Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.767{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A66B7951943A2A28924A7000DC69D131,SHA256=6827061CDD2FC012386F6B9DAA89DDC49EE9F6495FAD3B23E557AE0EA6D0C496,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041435Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:35.934{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D6FBBBFA137A77FC07E2E9F38B67868,SHA256=B745A40BECABE1E525FDECB9FFD84DCEF6A9E037562637B05050CCA342E3F27A,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029210Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7917-616D-D906-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029209Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029208Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029207Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029206Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029205Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029204Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029203Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7917-616D-D906-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029202Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029201Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029200Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029199Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.751{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7917-616D-D906-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029198Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.752{6F8252D3-7917-616D-D906-000000000502}3012C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000029197Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7917-616D-D806-000000000502}3132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029196Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029195Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029194Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029193Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029192Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029191Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029190Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029189Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029188Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029187Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-7917-616D-D806-000000000502}3132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029186Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.220{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7917-616D-D806-000000000502}3132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029185Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:35.221{6F8252D3-7917-616D-D806-000000000502}3132C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041434Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:35.075{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041433Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:35.075{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041432Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:35.075{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041431Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:35.075{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-5BA4-616D-0100-000000000402}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96ef2|C:\Windows\system32\kerberos.DLL+793e4|C:\Windows\system32\kerberos.DLL+1443f|C:\Windows\system32\lsasrv.dll+2e0d1|C:\Windows\system32\lsasrv.dll+2c294|C:\Windows\system32\lsasrv.dll+317e9|C:\Windows\system32\lsasrv.dll+2f147|C:\Windows\system32\lsasrv.dll+2e0d1|C:\Windows\system32\lsasrv.dll+16cad|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e 23542300x800000000000000041447Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:36.950{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3E2C7FC834510F3CFAC5ADD4CB7342E,SHA256=DF5442D005234AE804EDFBB38ED82B9E3A85EF75A2FF7A13F6415A7784DCCD3B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029214Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:36.767{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=22D14837C613803AC0FE8E16E42EBC20,SHA256=EFC5EB71610A35F9AB280A2A1529E6A1F735673F4D232E7422F1E9BC11AB4124,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029213Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:36.110{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B549F148A2113A6BD27BBD6B72D7B31A,SHA256=DEC0E802ED7AE9D8052B0CBE3E28D0C9745D61ACF2D97D8C628981C98A03A8E7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041446Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.953{8D4DD44E-5BA4-616D-0100-000000000402}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59006-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local445microsoft-ds 354300x800000000000000041445Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.952{8D4DD44E-5BA4-616D-0100-000000000402}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59006-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local445microsoft-ds 354300x800000000000000041444Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.858{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-185.attackrange.local59005-false10.0.1.14win-dc-185.attackrange.local389ldap 354300x800000000000000041443Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.858{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59005-false10.0.1.14win-dc-185.attackrange.local389ldap 354300x800000000000000041442Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.844{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59004-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000041441Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.844{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59004-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000041440Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.843{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59003-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local49666- 354300x800000000000000041439Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.843{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59003-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local49666- 354300x800000000000000041438Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.842{8D4DD44E-5BA9-616D-0D00-000000000402}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59002-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 354300x800000000000000041437Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:34.842{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59002-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 23542300x800000000000000041436Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:36.106{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A93BE1F75C626838691064915B9348DF,SHA256=48F49484671A614506970B62A47FA26E295EC4893907491A3F76A4381C185A6D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029215Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:37.813{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5DCFF95BA5A0A5FDD6B4F62C6CA17E6F,SHA256=DBDABDE9BB662B8B24CBF9862093E5C30EAB7883EC6B4F2F947CC6CA57F11CF7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041448Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:37.965{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5CC9463D18E9FD2E7C901E0734D0D56C,SHA256=DE20379B10EB18C706F997270EBEC058DD43DC0F28F12FB31178CC6E78C59020,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029217Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:38.860{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=851AC84139F9ECF2FC8263FDDA31036F,SHA256=95EBA1B3AB581C7A8FDFE71BC37238A9E0827AFEBD29E838E7DE5AB7EF1A9915,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041449Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:38.981{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=607F5770DE622D5915EB5F6A26471F9A,SHA256=23711AB2D984CD3E1ACFF38D793449840A85096CB281B130FBA62148025C80EE,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029216Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:36.584{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51146-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029218Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:39.892{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCC27792045BA9F27DBA1E4771D4BA45,SHA256=94AF9496FFECF2254E61F027F6EA6B206B61986C01A75E8EC912D8A938ED9561,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041451Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:39.981{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7A6019C32D56B6D770787A68AD617A1,SHA256=6B7D0037E999E21530910383231E8ECD53DAB9E019CA2683D14EF5FBEBA81A45,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041450Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:38.042{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59007-false10.0.1.12-8000- 23542300x800000000000000029219Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:40.985{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C96B10D868144ACE223AC55D41E6ABAB,SHA256=A65AF51A518B0E9BEAB858EFCE577D85C62042DAAA1368D4B6C34455F028989E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041452Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:40.996{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2C6D8ACDE816849A8F5F169E04EDFE5,SHA256=7654A7835D174C8E28F364D07F321A7F9EE53AD46FCC8936D4E9521E69EBF4FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029220Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:42.001{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C25495ECB21599313BC9FA4AD0F6CECB,SHA256=39558ADEEE916D6720D3043831143C5843CDBFFF943A49762F7D9C851E62B0A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041453Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:42.012{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD67BDF6E8026B73EC098233274237A1,SHA256=17EE35E90E1584858C63EEA44796D6EB33A807BF1659221E8EB713981361712A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029221Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:43.001{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B03B60BE6783AEF0542391A5DE7F847,SHA256=473F651A4078CA1A892D09649990458B28AB347CAED793FB3DA188070F809520,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041454Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:43.028{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E0CF8889F6A789A099328E3C75B247D,SHA256=0CD4907606F227B4F38B665291ABD83C64ACEF36DBD2A6AB2433075B595D2C1B,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029223Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:41.787{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51147-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029222Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:44.063{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C170527AD0D912F82FFE285E666D2262,SHA256=CADDEE7D5369C4FCE2E4A1DB984B7031204795B5FB104DF5887601260B60D3CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041455Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:44.028{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BB52142F2F7CB5B03B5BD7B5FEB9270,SHA256=0771383DDEB7FA83D4D20A3D4131FCC2FF15A0C4E8592A58B5BF864CA69D23AC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029224Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:45.095{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=894E13456289D9AFFFC49D50DCB4A934,SHA256=3E22E3C57925CD8912BFDB23BA5F9CDE5C816B9EC33C8A4B1BA3B239D377FAA5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041457Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:43.949{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59008-false10.0.1.12-8000- 23542300x800000000000000041456Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:45.043{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=73EDBE9E77088F6931CDC0923438C419,SHA256=EAB53D9D3C9F7550138BA49DCFB943F07E876B1D8D41194C294ECBEE5E9D400C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029225Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:46.110{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BB38E3B25490ACA7975CAE664B278FB,SHA256=ED10AF4367225ACA6DA4EEF2A2BD43F035AA69C61A13268E822F4313C6C48CB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041458Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:46.059{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=835E0DF7AFF57051EB46FA7D6CBAC325,SHA256=603BBC68C27E756C04D794653F7B90FB80FCCE9DF4A259D4A23E6013340A6AEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041461Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:47.059{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1443340B065CCD5A438D5DE51982761,SHA256=BAF65DB682920AB0FB29C23C5305B9753DFEF8663AEEBB0D8A9F0F996CD1FE36,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029227Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:47.112{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E9E782BF7C684319182934986614A82,SHA256=02AAD5558F16B8259BA641B8EEAB8D520151EBA88D8417F115F4EE2B1C02666B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029226Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:47.098{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-113MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041460Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:46.997{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C4472EBA2C930BEC79AB86B5F3FC9DBF,SHA256=97669851221475D1CA411563B445B5162F8C90E5C6CB702E8A5DF25DE9DBEE3C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041459Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:46.997{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9AB5BDB7B044CF45214F65AE1E8133D9,SHA256=199BC480F8FF8C9650787C96DA6615CC516DC34401A73F0F0EAEB92E0D16EDA2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029229Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:48.116{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D55B07E0EF49420AD2231E5EDA09CF0,SHA256=9141BE41292CA5D741B4D31A9C8401BDF73573961685982517FFBFE848278314,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000041465Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:39:48.403{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\60E60F09-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_60E60F09-0000-0000-0000-100000000000.XML 13241300x800000000000000041464Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:39:48.387{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\B282E4C4-BB5A-46C5-9F10-A3714310BED4\Config SourceDWORD (0x00000001) 13241300x800000000000000041463Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:39:48.387{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\B282E4C4-BB5A-46C5-9F10-A3714310BED4\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_B282E4C4-BB5A-46C5-9F10-A3714310BED4.XML 23542300x800000000000000041462Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.075{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=834E20DA7D7BD2696CB45B17D419EA1D,SHA256=1EF304D75B7D7FAAEB36835D5CED662453FC43650224DDB75958CFE32744E051,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029228Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:48.103{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-114MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041473Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.292{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59011-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000041472Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.292{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59011-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000041471Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.282{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59010-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 354300x800000000000000041470Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.282{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59010-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local389ldap 23542300x800000000000000041469Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:49.403{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C4472EBA2C930BEC79AB86B5F3FC9DBF,SHA256=97669851221475D1CA411563B445B5162F8C90E5C6CB702E8A5DF25DE9DBEE3C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041468Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.262{8D4DD44E-5BA9-616D-0D00-000000000402}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59009-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 354300x800000000000000041467Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:48.262{8D4DD44E-5BB9-616D-2E00-000000000402}3060C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59009-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 23542300x800000000000000041466Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:49.090{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E086C4E10936F9BEF47FAE66DC2F16E9,SHA256=A58D581E19F36646150A71C38C3EDEA7D3569BC0602C5EBF6C66F951591FE9EC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029231Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:47.682{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51148-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029230Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:49.165{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=207B9D09294583F327D2D6AB906DC1B1,SHA256=F33105FB8DC635FE1EA7A8155045C10CDC56520A9E54CE6DE382AB04068D95E2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029232Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:50.196{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8B22F3BB9C6C43F7AAD1A01F83693025,SHA256=A6254C2BA13D674C8D5116909BEBA286F1993C035AC4F1D14730D61D9766CF32,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041475Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:49.010{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59012-false10.0.1.12-8000- 23542300x800000000000000041474Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:50.106{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4EBFEBFCBECA967F50C7BD62477AEC1B,SHA256=45F919674E1AEA392D36D34E5578AE132757D3776609308F265D47A6A17101FC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041476Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:51.122{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F6C32937653F7088A171D7992F728F1E,SHA256=F40229A74161731010A9E48F50C4CA9777565AEFE7289C9DEAA8DDF0589E207D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029234Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:51.836{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=3C1E112E6C52075016CF932411E668A9,SHA256=32DB7BF426E03BB879365CC6241483DD7A9D6AACB73F30D72C1CD2E383E54500,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029233Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:51.211{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41B135258081815598B7C2D27A429D95,SHA256=367213FA99BAC157FAF5EF30D35F61285F5512AF6D93CDF814309945582215D6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041477Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:52.137{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3FA22A68C1529E3D6B182676460CA96,SHA256=0A7FCA91E4F9D3EBD1A5279E8E0FBDE5F1F32F67173E5715D338653D87E12D09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029235Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:52.243{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02E2E5092B34BA872D82CC154498C955,SHA256=FB52EEEB6E340FF45CF5B3ED909A9EC718BEE58970E14C25A7A6F1B09FA53E93,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041478Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:53.153{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32C5B03CDC0BEDFDB76F4D0D52475697,SHA256=209EB55EBC18EBACA518F3CCE73244D12E1EE9188248800541AAD2A82C67EB87,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029249Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:53.790{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBA-616D-1600-000000000502}1240C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029248Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:53.790{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBA-616D-1600-000000000502}1240C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029247Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:53.790{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBA-616D-1600-000000000502}1240C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 13241300x800000000000000029246Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000029245Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x006b3792) 13241300x800000000000000029244Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7c41d-0x3f4c99f2) 13241300x800000000000000029243Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7c425-0xa11101f2) 13241300x800000000000000029242Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7c42e-0x02d569f2) 13241300x800000000000000029241Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008) 13241300x800000000000000029240Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x006b3792) 13241300x800000000000000029239Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d7c41d-0x3f4c99f2) 13241300x800000000000000029238Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7c425-0xa11101f2) 13241300x800000000000000029237Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-SetValue2021-10-18 13:39:53.321{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d7c42e-0x02d569f2) 23542300x800000000000000029236Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:53.258{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E4F469A8884F0683F9EC69ED85D28C71,SHA256=3436E34AD3AE794FB995124A28339C0A22251CFE8CCC914E59CE019C74F0CEA5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041479Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:54.387{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=45EADEF557A369D1A9C5DEBB81E62131,SHA256=B546EBB655BBC749CA6866E8043F5B61C9911C97D5C5E2ABFE369E479977C9F5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029250Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:54.290{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=52D54FCA7C2D1225A9134ED60C398FE7,SHA256=8ABBAE00872C09421F5F7CA404CCF5D36AFFFCB5870836BF89CC61763115E9A2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041480Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:55.621{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=956CAC77AA94C637C85639424004FC66,SHA256=DF906FEF7E112BAE6F2552145E0C31ACD25E3902E4EBF0844DA477765853BF27,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029252Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:53.622{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51149-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029251Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:55.305{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C6FAAFAEC6F7DAB28326737A428B3638,SHA256=4156BC4BC24EC3EC28DE9F122B9363CA532E15F073229DE07FD80F3F0DE500A1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041481Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:56.747{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09E693A55827CD1512DE658C2E3C9ABE,SHA256=407E2D9C87FB80B308B6729EA22DE2E54F4DB1A94FBEC64D1A75284827560EBB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029253Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:56.368{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1185FC20082AED8C3A5192F017B4554D,SHA256=CE9DB6DCD90FFE1324B5B6F58478BBED1CF0C8651BF7DB20084632D90A44E6B4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041483Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:57.762{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=361813D7B4BF980756A13DC3FF552AF8,SHA256=C35E52093CFBE3E207B76A660B61C40B6E7C6A69EB091C060922F6E1E1761504,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029254Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:57.383{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0ED40C571EE51321DF80D022E11F69A5,SHA256=AA1484A7C80734F11914F90F0521DE8FC98BF2FB582524142C903E5E2D684CB3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041482Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:54.995{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59013-false10.0.1.12-8000- 23542300x800000000000000041484Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:58.762{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=937777F74FD9D7808800D24417B27E78,SHA256=9CDB426C137E480BC6763CE56C429D343FBB28D88E19C9F51EEE01F270F35D16,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029255Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:58.399{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=711DD224C4791905EA7D30FFE2B426A9,SHA256=2B9F6376DFD3DE9AA570C0CA9E02842A8CFEBF7AFA5A42E9A9D187812EC38877,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041485Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:39:59.809{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=438E4EB7638B1712195A6C8F4930CC07,SHA256=D4FAE920C68BEEAD9C864BB2C07B95E291435B1974E538D7FCE40BBD405E805C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029256Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:59.430{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D82CE6D499582E023932E9C9F1DD3AFA,SHA256=429CF087ED4589675ECA9668EF70EB0344DEC6F7BBE33487C9530A23B2CF457E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041486Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:00.887{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=92F4FAB1594B2E192DC937A1C18CF724,SHA256=4686FBBE6375AB74716EBA781FF71F206C3DC331D2727213E8183A585D0860B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029257Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:00.462{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2FC489775A7D8998665422254FE6727,SHA256=EA33B662982D5CA0A45947ECA6619C9BD36C9A859C50D79D76E1F13D09CA2724,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041489Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:01.918{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDCC5791DD9544DD701358651CD5E148,SHA256=42367E307E93A12A0013688B12FFD4AD7542AA511BD700533F992093911DAE71,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029259Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:39:59.622{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51150-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029258Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:01.493{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C8413BB6039162C1929CEAD6F74809CB,SHA256=46FB381C1E1B83AA830424108AA20E06BE95BEACD432683B7A18481D9AD6261F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041488Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:01.121{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5AE6231C24FDBAD545DA97DA9179F911,SHA256=1B7FC12165A7A9E9E6EE69AD24D3FFAA95724F58A67BBA9EBCAFF5AF14B56188,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041487Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:01.121{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3A9E7D4BB1EB56D560D349B6479B0087,SHA256=DDBF0E3447ED3C39B2CFEB191F4CD2EDA3E1E442F765661741B9DBC74C1860DF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041493Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:02.934{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C47DDBB31CB04E0FB83C98D075759977,SHA256=8C0964ED0E3C963606CD6526F6CD9764594257D190B3EA2BA5381D964BE1A0AF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041492Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:02.934{8D4DD44E-5BA9-616D-0D00-000000000402}9043884C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+fa21|c:\windows\system32\rpcss.dll+d6ee|c:\windows\system32\rpcss.dll+b877|c:\windows\system32\rpcss.dll+85f7|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029260Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:02.508{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A17E02D5FD6486BDCB85F65ABEDC7ED8,SHA256=F1641E89A4BA6B84883F695F58941E0340BBEC8F88EE5D243A2C09875A61A98A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041491Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:02.700{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=AD82D8E2CA57FEFC00332C574B74C6D8,SHA256=D59F39C0EDEE1ADD01C8EC73199B03C2DA5D12180DCA33235C984A18127F4DC5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041490Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:00.042{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59014-false10.0.1.12-8000- 23542300x800000000000000041494Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:03.965{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6D898147DD78E17C0C01159622DFD570,SHA256=F9453F9F0934786F349B165CC27B7A6BF50DF62EE37BA209F13D8D930300D98D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029261Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:03.524{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8C8A3D56A3A08D50AD2DB16E7CB17C47,SHA256=1B997398D221A7FE6508181B8DF0911F8A363ABBCE60BA37FC03189F0059CFA9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041495Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:04.981{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=49D4CFCD317ED7072E0E4F5B001741FC,SHA256=7F41F43F431DC10233C0DF0E309DC22FFC4F3E3B6073967D95089A0F66FC05C8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029262Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:04.571{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B23A9B65194CA488FF051D09CD96FBE0,SHA256=84811487085A8293A616BEC6428A2F59DD2C373535E9F9F83F829850AC9917FA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029263Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:05.587{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE8303709EF1557F66BF949C28AB005E,SHA256=7110F5D9960E5D75F8440FFF46D14BE691B32229F9EE0F2B55575A9DA38FB788,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029264Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:06.634{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D475DDE6E5D9B22D1064593A5461F2A3,SHA256=259DD52F7F0F5DBFD9CD628E4C04B588A245FEDB1DA0E469FF1DD9B9D843A4D1,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041523Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7936-616D-1509-000000000402}5100C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041522Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041521Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041520Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041519Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041518Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041517Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041516Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041515Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041514Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041513Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7936-616D-1509-000000000402}5100C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041512Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.840{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7936-616D-1509-000000000402}5100C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041511Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.841{8D4DD44E-7936-616D-1509-000000000402}5100C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041510Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.653{8D4DD44E-7936-616D-1409-000000000402}18484392C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041509Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7936-616D-1409-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041508Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041507Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041506Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041505Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041504Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041503Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041502Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041501Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041500Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041499Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7936-616D-1409-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041498Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.340{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7936-616D-1409-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041497Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.341{8D4DD44E-7936-616D-1409-000000000402}1848C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041496Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.012{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EDA85522C93DECBCAAAE95F195A1196B,SHA256=12F9376EBB2AF8E8326AA7984EBEE91653F7EE7DDDFB2DCD4B653B14A2A31406,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029266Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:07.646{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E67721E727EDA686ADBF75232DB9C67F,SHA256=8D1FB0632FE285D57559864C5E574F207BF99D1DFC1E07B7337C0B5885D50434,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041541Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.751{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041540Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:06.041{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59015-false10.0.1.12-8000- 10341000x800000000000000041539Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7937-616D-1609-000000000402}3804C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041538Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8581197AC1D1A488447993923ED40F66,SHA256=3FE15B89B8EA7CADB16F7B32D324E150779198F0E307B9FCBA88A20C600E727B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041537Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041536Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041535Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041534Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041533Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041532Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041531Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041530Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041529Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041528Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7937-616D-1609-000000000402}3804C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041527Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7937-616D-1609-000000000402}3804C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041526Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.472{8D4DD44E-7937-616D-1609-000000000402}3804C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041525Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A73390E69C05D9B09EC26DD69A03C010,SHA256=66A31C0663A6892ABA9FB6650B058B8A98A310A4D697EDA32B0B8BFE038A4333,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041524Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.470{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5AE6231C24FDBAD545DA97DA9179F911,SHA256=1B7FC12165A7A9E9E6EE69AD24D3FFAA95724F58A67BBA9EBCAFF5AF14B56188,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029265Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:04.747{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51151-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029268Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:08.662{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6FC0D1D8291B752FBCACBA927D9B0030,SHA256=AC329156EC37C16CC0E194D6E6E8EE9716E714C501A9DE5E3960F8D06C4688DF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041557Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.720{8D4DD44E-7938-616D-1709-000000000402}34281036C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041556Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.595{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18CBA2FD9910A4E3B649CF0427556594,SHA256=3AF740CE4EF8A06DE6831278EC8BEED27948D17C821C18D1D326D23B9CE4DBDD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041555Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.502{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8581197AC1D1A488447993923ED40F66,SHA256=3FE15B89B8EA7CADB16F7B32D324E150779198F0E307B9FCBA88A20C600E727B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029267Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:08.381{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041554Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7938-616D-1709-000000000402}3428C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041553Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041552Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041551Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041550Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041549Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041548Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041547Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041546Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041545Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041544Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7938-616D-1709-000000000402}3428C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041543Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7938-616D-1709-000000000402}3428C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041542Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:08.470{8D4DD44E-7938-616D-1709-000000000402}3428C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041586Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7939-616D-1909-000000000402}3136C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041585Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041584Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041583Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041582Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041581Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041580Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041579Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041578Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7939-616D-1909-000000000402}3136C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041577Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041576Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041575Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.938{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7939-616D-1909-000000000402}3136C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041574Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.939{8D4DD44E-7939-616D-1909-000000000402}3136C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000041573Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:07.608{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59016-false10.0.1.12-8089- 10341000x800000000000000041572Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.673{8D4DD44E-7939-616D-1809-000000000402}45284704C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041571Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.548{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6BBB4579D676D571DB5D57551C9CD704,SHA256=E4A2F379477D32B32ECD07CE4023274DAA55BEAED32083CE63BE484F6B955986,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029269Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:09.678{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F566B94978F2287A5018C444FC23E3BF,SHA256=DF38B8E6DB96BFDF302628CA06002E1869BC7C7E72DD91B59144A4A5CF93D590,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041570Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7939-616D-1809-000000000402}4528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041569Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041568Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041567Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041566Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041565Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041564Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041563Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041562Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041561Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041560Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7939-616D-1809-000000000402}4528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041559Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.438{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7939-616D-1809-000000000402}4528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041558Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:09.439{8D4DD44E-7939-616D-1809-000000000402}4528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041589Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:10.548{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6626319DA91A217BFF7F7AC763D419EA,SHA256=5755E30FA032191D42BEB31978611242B38D36D20818E0EE2E90757E624877A7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029271Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:10.693{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC212DB1441ACEB0352ED0FDED7D33BC,SHA256=070B3CB8E378665B1B72D5032699144ACCDE2C1285AA318A12216FCD61451692,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041588Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:10.485{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=63B8F03E926A446AC0771C4FB47F9334,SHA256=F0D4DED29227B2217FB32026E23D3FE7D33975931FDEA5720D82EABA1F36DFFB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041587Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:10.110{8D4DD44E-7939-616D-1909-000000000402}31365060C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 354300x800000000000000029270Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:07.916{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51152-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 10341000x800000000000000041603Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-793B-616D-1A09-000000000402}2120C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041602Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041601Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041600Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041599Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041598Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041597Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041596Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041595Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041594Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041593Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-793B-616D-1A09-000000000402}2120C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041592Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.954{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-793B-616D-1A09-000000000402}2120C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041591Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.955{8D4DD44E-793B-616D-1A09-000000000402}2120C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041590Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.641{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6B02C6530C0231149DB4587231FF357A,SHA256=2D834EC47836EA423D9640B43A360E4ADFC31E985B79E6C2122F7640BB8861CA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029272Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:11.756{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8BB1C5E0BE22422B6D38B91D9EA356A1,SHA256=ACCCE0E537ECE69AC42890F31043008B345FDFCC8E6A76E06D30892930F9924C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041606Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:12.969{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B372D91B7E4E10569892BED8440EB974,SHA256=4765BE8F4489F058DFAB659BFCB5062FE4A5383AA0D62C72FCA4D9F1F55A2C49,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041605Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:11.124{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59017-false10.0.1.12-8000- 23542300x800000000000000041604Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:12.782{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41E2CDD7856E01F0E2DAFDA18A99A016,SHA256=A62F8D380E787937EE1E6B3CA82DFDFD373514AA84336C94D7B1172E18D4C8E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029274Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:12.803{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03DE0B7CC353D2F5C27E3BEB255054BD,SHA256=9727650FF24B74D8637194CE68B9C86A80CA0DB5592BA1E9BFB2E5A12AFAF1B6,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029273Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:10.744{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51153-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041607Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:13.813{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E733153203AD5368FD53D56FCB61AB64,SHA256=AB3192472965FB0248EC2E47C3913AA24FE4434FF5B521A18D280533B658189C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029275Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:13.818{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F34A44EC94CEA640BA0385482D79CAC,SHA256=6D608B1B634F7183D2B989735E2695897341A526734A3A5674FCD9B20735638C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029276Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:14.834{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=529DE4243D39D798836DE216FA8E57E8,SHA256=78671FCBA96260CA517104B1817DC9207491F189B227711D14A00162655280D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029277Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:15.865{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D718415F7FCFB79A6C712DD11ED487F,SHA256=ACA39F061E2091C361F8627A2E697023AF31A1FDD91766FC92E4D224BFE88860,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041608Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:15.048{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4958D842285E38A90D9405ACBF1109F2,SHA256=33A9BF5061C4213A6897E83993838994E67D1A0A668653AF6B5F6341CD301877,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029278Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:16.881{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85F921E651AEC8F7CF20D45AD3F23340,SHA256=6545AABE3539FAEEAA2BBA374682BB340419A82D0C1D4E6085A9DE5B8086BF7E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041609Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:16.079{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9273575AFC29358E7AC2BAE4351CAB99,SHA256=9F9893B537BA85E8A988FB25328A60DBA17A14CA17CF928C4C1E635FB29E92C3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029279Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:17.881{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC84321C408DD871200E3BCA7763C7C7,SHA256=1A42C2BDB6F2BCC3914FED7BC80F08063AF6631972D99032BBECAB19791BF13B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041610Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:17.094{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8465BECEB2BEC8F3278F5E6278596BDF,SHA256=D30625A6DCE99833534C979AE7728E33B4635607AB17E3E41F1AE8D1110DDBCC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029281Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:18.928{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F0AC488ECFA67A241D4E1AA5BCDBC156,SHA256=62EB1D5E5B2367FD029CCE09BD22F367DCA2036A0484B3AD1A5FBE53B78EABE8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041614Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:16.921{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59018-false10.0.1.12-8000- 23542300x800000000000000041613Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:18.157{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4990D463780C1DE11045532C22960860,SHA256=11A8832DE75E6905F8E05977ABFA91C689BFC51A9018F3C25D477F32C835CB96,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041612Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:18.157{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5078F0357957E8990ED42E6978D6976F,SHA256=855F4111E0349D6D39589F8297DF80649735B03EA338D1FDE9EA9CFEE21B9A7A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041611Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:18.110{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A7A17E78A3456E8C9046168C2396A8CA,SHA256=16F87E18A813804315E407C7C796B525538AAE05789F2E2605269D30C186D21F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029280Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:16.650{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51154-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029282Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:19.959{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB8183E2C02D6ADCF882930E8B64E570,SHA256=1FBCA808A51D0C9C3A78CCFCE9E30BC212369583E579F351DC1DAFFA75C40D57,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041615Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:19.188{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FEB9C3D8B040770C00C0C28EDB29051D,SHA256=F8A5ABBADEEBCC4656857FBAF992174171624FFEFE5D9478772B826C65176287,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029286Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:20.975{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8D195B4A635C791A8361A7D9CF2A55C8,SHA256=C660619B70403B591694D53E7E01608EDB616D08AB44EA558E9493905B83C20C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041616Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:20.204{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=979F6896F2617F17A70FC248B4867553,SHA256=8BFE52EA0C3233EFE1E63B8042B1CE6A2F6173EB30D912A4E6A10262F4927920,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029285Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:18.822{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com59625-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029284Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:20.771{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A64700978A7916E82A4B727117029C9,SHA256=84DB30BAB5A97D11F30D9DF54D54007903B0B09D18D0016762986081E0C56552,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029283Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:20.771{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E3EB84A3E8B8CC2B4AA49901CD53D6F0,SHA256=FEB257D2B618C9096BE19D33067A07482B75FBE04AA6279295AB623F8A251ECE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029289Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:21.990{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6E18922EE24055CA180D181DA34FD36D,SHA256=4BC05B2C3AAF83FE78D59E6ED381049E111C08988111F8EA47C91AAFB0AC22E9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041620Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:21.235{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D73AEA1C94F3A21F22DD4D4703C99DF0,SHA256=0D4B75B87E4137B7070378E365F8F1E9C7F69168FFC8721F2DB53E0CDF9F8BB1,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029288Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:19.314{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51156-false10.0.1.14ip-10-0-1-14.eu-central-1.compute.internal49676- 354300x800000000000000029287Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:19.313{6F8252D3-5DB9-616D-0B00-000000000502}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51155-false10.0.1.14ip-10-0-1-14.eu-central-1.compute.internal135epmap 23542300x800000000000000041619Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:21.204{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4990D463780C1DE11045532C22960860,SHA256=11A8832DE75E6905F8E05977ABFA91C689BFC51A9018F3C25D477F32C835CB96,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041618Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:19.632{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal51156-false10.0.1.14win-dc-185.attackrange.local49676- 354300x800000000000000041617Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:19.631{8D4DD44E-5BA9-616D-0D00-000000000402}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse10.0.1.15ip-10-0-1-15.eu-central-1.compute.internal51155-false10.0.1.14win-dc-185.attackrange.local135epmap 23542300x800000000000000041621Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:22.266{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36F08237EE1064FC05D54DB7A1074526,SHA256=B0E8364CB494F283156FAB4BD1592B3C0D0A48FC684EE2D4A855DFE4DB05B520,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041622Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:23.282{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E876B22C1E23E22760FF6B6CD80A4445,SHA256=E953A503EC9799A5C17079B83C1E840D63264F2416B47F1DBC10D86E8AA9D729,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029292Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:21.277{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com59819-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029291Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:23.162{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A64700978A7916E82A4B727117029C9,SHA256=84DB30BAB5A97D11F30D9DF54D54007903B0B09D18D0016762986081E0C56552,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029290Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:23.021{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E844B9AF10E29DE36F63D9043BAB0246,SHA256=95847C2DE37A731A2FDAD1531B4396439B73A2AC86398C289BB708EDEBADAFC9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041624Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:24.313{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=998AAA3EC001C3585CC5D36B58695EA5,SHA256=AE7BFD6D8E1F148663378BA27940DB4B1639892295E381E0F29C987A5DBA3D65,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029296Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:24.975{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C825E74CA0BF91F06D7C4CB549A1E81D,SHA256=FA7253610EA961040CC2664BE779917634AE38470B779C10EFAAB15E120CB1E5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029295Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:23.083{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com59954-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029294Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:22.618{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51157-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029293Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:24.053{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=874441ACB7390FD68C1DE06CA638A8A8,SHA256=621BCA4EA91C5B5E48A4ECFDFA48B9861314E5E46733074FDF9FB165F6738254,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041623Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:21.936{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59019-false10.0.1.12-8000- 23542300x800000000000000041625Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:25.329{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E42BAD6E0A12F53412D3C48CE917E1B,SHA256=EDC3CF88365411B4D4CD6C41195E74C24131FA408D28991BE91B11F5ECFDE4DD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029297Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:25.084{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A7A37C4F8240A6AF62FA9D1B9EDFF04,SHA256=B8C96BD7CB029D2FE283912691AD09FFC52CA2641F15801C4D1D623D164B1840,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041627Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:26.895{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-122MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041626Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:26.360{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ACD419417DE0E2F226AF559687167557,SHA256=4ED731E6329CB76EDFE1965859E9C63322D45B62B2C5EB326F507B3FE6E3CB92,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029299Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:26.678{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3E6C9C1F3DE71C77207326F5AB8AD0EE,SHA256=9D526972F275210B736AE345E99A732CEC3660308A5951606E5852BC496E05C2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029298Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:26.115{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D164C8BD096DFF8FEF15AD7C0CA1061,SHA256=276394D906E13EB537135F8FB9FB7CAE7B3BFE69D732F24703A555664655DA67,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041629Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:27.894{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-123MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041628Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:27.596{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A6700B7144C7BD56902BBD25ACD84F7,SHA256=265B889C5AECB6F5AA93944D19337BFED156A3A0C0BAF1388AAECC8940A0ABB8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029301Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:24.778{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com60091-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029300Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:27.117{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=10E5853B06A73F8A26C0BA36F1DAE29B,SHA256=7EB8DADBCAC6834B90FBC7C2CF41730A21FF2B0D63755BBA29090E1AAF874F10,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041631Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:28.598{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA5198B1D137678F5F8E18CBCC683773,SHA256=230389169ED9EC3B9FBE91273DD703361D0AC6ECC5A61B81BBA9185D09353018,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029302Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:28.132{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E31FE43C76A598A49D9FDE22CECCD2F3,SHA256=F7C8272021B3A7B3B9B8F7CFCFB1D830130A006E2188D1487F97A164627EBDEA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041630Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:26.954{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59020-false10.0.1.12-8000- 23542300x800000000000000041632Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:29.613{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=813D3B1C272B42018C52A68EA46B001C,SHA256=E4E62642B9B13BFDCF870DCC18C7B9DDD4761B276D4EA9357481D668E9EEA83F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029304Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:29.226{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9ECA9E94D3F4BEB979288B2D555FA10A,SHA256=D93317CCB8DD1CDD96FAA64189B7972377A00DB92C40B0A77526F871C255BF37,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029303Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:29.148{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E44B955DD4CAC36498B5C4871451512E,SHA256=44148C0B58EC8B9CB43A6EDFB5CF86E4FBCA916EEF4CC98C1275D468FDFE2F52,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029307Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:30.257{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2211894111F1A89F881E5ADBED525443,SHA256=5E29D042DDC054BA045C3D9F16AB0530FF91C87ED288E20A6792D60864784658,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041633Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:30.613{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A643D49C1A9A1BFED1EB091CDCE9972F,SHA256=4EDC1E32E9A3F8C462DDB00C93988322837A56BA274D70900591705AAC8273D3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029306Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:27.620{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51158-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000029305Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:27.258{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com60292-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041634Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:31.629{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5C49C8AC360D60DB66CE0D938591BD5,SHA256=8F7B683AB195423E846D369EDFD83C72910F8F40C7DF64520864DE9CDFE450D7,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029323Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.679{6F8252D3-794F-616D-DA06-000000000502}30803540C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029322Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-794F-616D-DA06-000000000502}3080C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029321Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029320Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029319Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029318Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029317Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029316Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029315Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029314Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029313Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029312Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-794F-616D-DA06-000000000502}3080C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029311Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.476{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-794F-616D-DA06-000000000502}3080C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029310Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.477{6F8252D3-794F-616D-DA06-000000000502}3080C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029309Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.273{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=316F891345EB1A07F35358CE6889EEAC,SHA256=A8E7E027D8049CDD2481AA952BDDA582C6987C1936F5C1AADA67BB16D8BC9665,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029308Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.211{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8201908E7F979A86EC8ADE2E2E9D1725,SHA256=46A822D3018CA7935E4A606E0ADA4F4780A95AA68C0AA30E433A2B65F2BFEC2A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041635Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:32.644{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0370F895D008039965E1193C67590EFE,SHA256=C00DA58781ADC41D5909D29E96B95A6C01AA72872A166E90DC0085A41C74A888,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029352Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7950-616D-DC06-000000000502}632C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029351Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029350Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029349Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029348Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029347Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029346Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029345Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029344Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029343Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029342Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7950-616D-DC06-000000000502}632C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029341Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.648{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7950-616D-DC06-000000000502}632C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029340Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.649{6F8252D3-7950-616D-DC06-000000000502}632C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029339Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.507{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5FF7351E994157740D042E5FE656152A,SHA256=FC896426AD6A4AF1B7EF818251B0BFA9F042D7536BDB42029D8FAE0F24A82984,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029338Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.336{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=835F5471E226E0BDFA91A8BBD4C13524,SHA256=5057ABEE101F779C3E55D0847C5E164F45B9D2BCA01F0992AAADE37D0D4C4CDF,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029337Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7950-616D-DB06-000000000502}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029336Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029335Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029334Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029333Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029332Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029331Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029330Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029329Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029328Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029327Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7950-616D-DB06-000000000502}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029326Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.148{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7950-616D-DB06-000000000502}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029325Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:32.149{6F8252D3-7950-616D-DB06-000000000502}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000029324Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:29.321{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com60454-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041641Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:33.660{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0DC75F299A40FA1454B128550940114,SHA256=988132C093B1136D6B0EBC281AFDFD186B2BC351CF19F74A39DB4B79AAE20C87,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029369Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.820{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8F6C79FEACDDDFE1603B16FC781AAD97,SHA256=627195A62339C6B2EE4456D70E1805A91CB21760F526E03EC961080F2D05F88F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029368Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.742{6F8252D3-7951-616D-DD06-000000000502}10803652C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029367Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7951-616D-DD06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029366Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029365Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029364Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029363Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029362Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029361Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029360Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029359Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029358Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029357Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-7951-616D-DD06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029356Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.539{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7951-616D-DD06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029355Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.540{6F8252D3-7951-616D-DD06-000000000502}1080C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029354Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.351{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F85C318AF224C5C785165F3CD7532AA,SHA256=F09D6AAEF495F330FD6BA7097584141F6EFC387A81AA71B774A079261001F034,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041640Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:31.970{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local59022-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000041639Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:31.970{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local59022-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000041638Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:31.955{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59021-false10.0.1.12-8000- 23542300x800000000000000041637Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:33.113{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BE89EADC41DF2638B15C29C58D12E17A,SHA256=4D42D59B288EBB525DCE05F6C136B1246B0EC922D5E9A527D9B6119A61F5CD50,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041636Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:33.113{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=825CC36CA950B0BBEE35D76AEFC30AAA,SHA256=E66790D629AF91255FF9224F3F9B9E94A1B63747ED3CE498BC65A986FEC5CCC0,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029353Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:31.445{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com60617-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041642Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:34.676{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76F7CA455F0B8B973090C58975A88849,SHA256=E849C0F0FAFD6E215FE70F57B6D7C42DE1271FE978A1BBF88E8DF9917F85D70A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029385Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.992{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0683D7A089BBE0F281FE807D01B69E47,SHA256=CC0FED9BB808174B01ACA8AE4C00EEEC457C8DF3D5CB1A764BC429110D1DC66F,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029384Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.914{6F8252D3-7952-616D-DE06-000000000502}17441540C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029383Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7952-616D-DE06-000000000502}1744C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029382Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029381Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029380Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029379Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029378Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029377Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029376Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029375Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029374Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029373Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-7952-616D-DE06-000000000502}1744C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029372Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.742{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7952-616D-DE06-000000000502}1744C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029371Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.743{6F8252D3-7952-616D-DE06-000000000502}1744C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029370Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:34.398{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=73C34770469DFAE32761D8F714D8EA04,SHA256=980C40EF87965142B93DAA47B56B867D950D1A806D62DEB67C642D341E49AD67,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041643Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:35.676{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FCF0890E474444AD284ABDFEDB8E78F2,SHA256=5C2C3247A7A5D98104A9DC4A3479E351847747BCFABA849FE8B849756C730B59,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029401Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.617{6F8252D3-7953-616D-DF06-000000000502}25202312C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029400Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ABA1BA5486557ECE1CEA2E067A0E4233,SHA256=240EE6E58FD7EDD17F1075C208FBA38251DDFFA73A57ACE83A3F57C96CBE2BBD,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029399Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7953-616D-DF06-000000000502}2520C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029398Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029397Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029396Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029395Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029394Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029393Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029392Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029391Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029390Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029389Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7953-616D-DF06-000000000502}2520C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029388Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7953-616D-DF06-000000000502}2520C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029387Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.414{6F8252D3-7953-616D-DF06-000000000502}2520C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000029386Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.104{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com60753-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041644Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:36.691{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C62AA1A1DDABECE138DB2C15E1147C86,SHA256=34C1EF0E731C57F8EB10C070C196D7BCCB9F77563F1626D529EB354BC897A521,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029417Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.601{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9FC62F152718483B525991F93793332,SHA256=D586F6C74EFCCC4892210A1B4EF1A934F87587761FFF027F383F470DE0F601D3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029416Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.414{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=151FC5E924686FCFF79963111A0D01CF,SHA256=85120C2A11FF4AD67E007D1E18EFB4FEEEDE82FA7234C094823530A1385AC13C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029415Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:33.636{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51159-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 10341000x800000000000000029414Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7954-616D-E006-000000000502}2108C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029413Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029412Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029411Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029410Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029409Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029408Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029407Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029406Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029405Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029404Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-7954-616D-E006-000000000502}2108C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029403Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7954-616D-E006-000000000502}2108C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029402Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.086{6F8252D3-7954-616D-E006-000000000502}2108C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041645Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:37.707{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3E92F7B56CD083A9D7D65D178091FBC0,SHA256=39AE750B3D14E9AFA75831DDBEBA7CD7A32E4A9AE8AC715EE93206D8F344CD58,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029419Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:35.101{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com60913-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029418Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:37.429{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=847FF7F665F6F2B59A009A9D1324A010,SHA256=CC2457548182F9BC1D71DCA000BABE3724CA9F2E550BCF02C91DB10C8CB5335E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041647Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:38.722{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC454E402E9E179C1766C44F6DCF6B69,SHA256=F13293E089DBC18DB64847844B2130409EBC25120EB6EDA2E969BCC87F258BBE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029421Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:38.836{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=137F34F96CA7180194F1ED512E8F78F8,SHA256=B2AC2F03B68FFAEB45E77184202F35C5E75B6FAF0F8CA2035B96E200502F96BF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029420Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:38.476{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D555417B3F5E3863340F12FA7090572D,SHA256=FE117359821450223538ACD6A74AD7375F760D18D3B020179B143140CC875127,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041646Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:37.049{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59023-false10.0.1.12-8000- 23542300x800000000000000041648Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:39.722{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7F2CBE6B85C72B8748F497D07132709B,SHA256=AB55606FEBF535C48D5E4D7FAAB762637656777FA848F7DAF5FAF88724042A11,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029423Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:39.507{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5D6D8F6BCD43BD2AABD96BA1D11E2801,SHA256=3D8180234C15C5F65001A8F00E0FD8AE26EC3DA98D6A83878B41F1591A15C53D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029422Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:36.933{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com61046-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041649Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:40.738{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C1163B3B318DA20E25DFC17C55DBE047,SHA256=8995DC70B71187437A788098D5F55E02F7CD29BA1A9ED423E8B12AD931792AAD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029424Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:40.523{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24B590F2241D091CEF177DA075683F8B,SHA256=0E38610A28D1ACE441DA95D13680E438977720EE484E4F00073C5DD3B2270F96,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041650Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:41.754{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBC0987EEECF244672E3A159CA7490A9,SHA256=B4B93D7678FD10EE54FE271D4A8D8C70BAD0B6F345071189E48E11C3C8D1F966,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029428Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:41.539{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC94AA9D91E44F88251FAEF749FB9779,SHA256=D74A292E612920E36E9E1DEDA9A453534B4BE88C2055AC57DFED0F6F78C9320E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029427Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:39.350{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com61234-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029426Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:38.760{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51160-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029425Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:41.242{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BD464EFAE5DE98CF182F63B35703BACF,SHA256=0351239AA5F2EEC195838950D1FD40285D31D78FD04076A422F3603DE16DA685,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041651Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:42.754{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B6C9E0C78350F4372599E16E79646D81,SHA256=0CBD7ED68D2E5A0911980B1EC199593F464297BE2B079270AD059CDF0BCB6BAE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029429Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:42.554{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDAFA7BD7608BA0D9763596D8C70DF9A,SHA256=798F1BFE01DC4310615C389347B586D8374CF221C9DD9EC2D89E652401742CDB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041652Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:43.769{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA5A7D9564D2B49E49B58467E814F5A4,SHA256=843DEEB8E00991E0A13217A44B8BB3B8BFE69F08A271AD09CA163D435EF3E357,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029432Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:41.678{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com61415-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029431Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:43.570{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D144B28A8061EE01D7838FD45BD0F71D,SHA256=0FD8455F19E0F8F370F8936F4D3D659E18659A99DF5E00B89B60066E4DDB49A4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029430Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:43.570{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A8BA289173381BA8A1733C819BBE3E3,SHA256=6E5E1816EFF9569AF179EF53F131E03C8DAD96BC3BD1DAED560BFCF906C5A270,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041654Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:42.986{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59024-false10.0.1.12-8000- 23542300x800000000000000041653Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:44.770{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=635CAB1D92E290012BFABA9F67D81799,SHA256=02B3AB7B89D6AC5EA136D7E88D33D822CBBCF2867F2370BB810A594761190906,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029433Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:44.586{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5CAB60839E3CA1E8DE46C9519CF3B747,SHA256=956517F125E89A8258BCA036537935E71C129AC95501398FE857CF728B4B7EAB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041655Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:45.785{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7749BAA1D253EF43533ADCF86378CE4E,SHA256=C0FF97E4EB7BB94DFED06D3DDFA0B2101738C4CF699C19F6FF8CA17365D542BB,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029435Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:45.695{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=73F306EAA1ECAA727FF2FF7D9AC68511,SHA256=F867D1A309D282B3908717A1C6C8372F1198DDA110E7911EEA4AE5D9320D9513,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029434Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:45.617{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E63FBF41041998314AFEC208E87C72D6,SHA256=B80E996E775FF289FCB31126EE4FB102644F529683770F3B281C08698C5156E1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041656Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:46.801{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=54B34F1AEE6DBB401D8B27DB90F523D5,SHA256=9A3682B55E8AE62916EB254280049371FC68222CA32FDAAD7560120F1A88A6DF,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029437Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:43.788{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com61588-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029436Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:46.633{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A4EAC30676AA9332CD98F499106E4DB9,SHA256=54CC29CDAD425B431F5B6443BBAFB393667DBEB50F4BF986B5506DC1C9E591C0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041657Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:47.809{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=49703300D534FAE1665F916346D5B035,SHA256=AE8C8065FCDBA42255C94A4D803C4C8581D485221E1C1138437B2E75BE176F15,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029441Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:45.616{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com61724-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029440Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:44.760{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51161-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029439Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:47.658{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=747ABB096720DCD89FF5945E1ECD0A28,SHA256=5E8A7343FD444D584F406120E50ABF7F2EF0CD0749076B6F7638228C742EE0F7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029438Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:47.533{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EC1C4D90FB0B77A5A8E9D4F543C8FFDC,SHA256=A4400D0A753F6900A6BD40FF3D254DAC5EA9F508D623AF8C55B4F0C7C8976E11,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041658Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:48.825{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8FC42FE5023C6BCCF0B537E5700504EB,SHA256=5186A9D64BDE965356586FD76F1EC38D7B556E8640FFFF2386602D18ECB82253,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029443Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:48.689{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=53ADA821FE43C3B759A2EA1F3EEDAF61,SHA256=9DAA04C307BA8890FF7E8F6D95841801A68DF2B4276D1F236C2AD2BBDCD53DA7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029442Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:48.631{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-114MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041659Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:49.841{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A23C88A2B9B64D51A145A77C48E84ED6,SHA256=16952E5739805282BFF7AFF3938E71DDD2B1B072DC1BDA000C62B8D79205CE7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029447Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:49.926{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C551AB66BE991ED9D8EA5A70BAF74E46,SHA256=0E60889B7767C6C32D0C2EE7FCECED8F0098D51F0F5D7E7699CFF7AB5F42B6B9,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029446Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:48.015{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com61916-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029445Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:49.708{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E64FA19CCEC2D71C417E79BE73927DC9,SHA256=7439EB3A4E328FDA0D66FB4F634150AD96BC21F1530ED0DC8EE6A5F83007E7A6,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029444Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:49.643{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-115MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041661Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:50.856{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8BB272B77DA24A5019B39BF9272A7F2,SHA256=E2A656DAF967EA1FA91C0B984769CA7B85744D4A4E6AFB76451B5D204FF1A1E0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029448Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:50.710{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32806C1F7012E4041360CF677BE9DA7C,SHA256=F82946B82F0AAC5453B3661691B459C39C8187BF4D761E5CA9AC9652BAFE0A2D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041660Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:48.073{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59025-false10.0.1.12-8000- 23542300x800000000000000041662Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:51.872{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=881E8B691BA153B130B53C8FCA8BAE6C,SHA256=3626065DE900A3754D7B6EF6F2CFB78B7A641588CAA01E83A25EAEF87170B2FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029450Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:51.851{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=6DD44E0DEF2C2A105503EC13CB152609,SHA256=9190692198821499363649288EBB455D12CC3E2EA934489CF93BD681DA89FA5F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029449Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:51.726{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BD45AB56438564C9F08C860582D10AA8,SHA256=F77E072990C8BCBA6D25E0D1C27B49DDEC7712F215728370EA3C8ABAC200E84B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029452Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:52.757{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA266BB3629727D09F312E8BBDFBA298,SHA256=A739055E780E27ED1091771A2A2FE49DF66DDE2894C6B4C42A052E8006089D0F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041663Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:52.887{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD34158786ABEFC03E849E906032EA9D,SHA256=EB83CA1D9D4E1663269DDA3236AD70870A14A4A962E3D75AEA547FCAA2DB13F1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029451Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:52.241{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=79239C225FCB591430BE547ECA76BFFA,SHA256=F8DAFEA6DB408BB5F9D43F8BBAF8293EF56AFAE16684546B469503E229C20F99,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041664Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:53.903{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=93BCF9FF84D9D227C03FAD5766D305E5,SHA256=5B3D9229F1A7D1CADB86FB23110BC7FAF53EAE479BC4B90BCF5E84EB697DCF69,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029455Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:53.804{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D3A885139581A59C564C1BDAC678D5C7,SHA256=08910C7487BEA9BE9FF76F96E1D92A945F0877BA4AF513E94CDE51AC8A76074E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029454Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:50.603{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51162-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000029453Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:50.344{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com62097-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041665Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:54.919{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF54A47107585DC61A34D02C66A4D47C,SHA256=A3C4381E8E71EE338AE38B30E3B0E7EB22AF6C3F2E832ADDF98FFC89690233F2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029457Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:54.835{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11D345F141F32C06ECA8AD4E3FEDE938,SHA256=97F9DB976FA98F365FCA03A5F127F9A10F1E4FC305CC313AABFABD3078730921,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029456Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:54.522{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B900302995E82D283EE6963FE61CECCA,SHA256=A74504A18D3264B9091C171314D77448F2415E0078C08EFEC0F64D9471DE99CF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041666Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:55.934{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A143C287CB8114713DAE85BF48B889A,SHA256=DEF3DE339B2B496C8C78C13C0CEF6BB9CFE735A17C6EA50374D4AF7888F6CBC1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029459Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:55.851{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84402985250DCFDBBD6FFEF9AFAD7736,SHA256=A60B06A43F4AF84176D1A5C6AB77648DC15128BFE69FA61AFD6F4F07A9334D05,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029458Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:52.580{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com62268-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029460Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:56.882{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBAE744607825BC750632B6835BBDE2C,SHA256=8074B3E930348FD46D45A6495CF170F3A0FB4478A16D6294FA13758B9CDDBFB1,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041668Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:56.934{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B7F71AB5F94290B4621F3C768854DCD,SHA256=D659E807703DEEFD16EC5DB7194512567D6A37A9B0CE9487E55A63077C58A1DC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041667Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:54.042{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59026-false10.0.1.12-8000- 23542300x800000000000000029463Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:57.976{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AAEF3607EF3B776841EC73181D4C1029,SHA256=B6D4F8CDC5A0F6D47CFA781B1C4B6ECDAD3FE477305D1EC6CAAB8AFECBE86185,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041669Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:57.950{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FD5DD4DB0F683413771A9065E0459BA,SHA256=B0F4E936CB12173CE0ACF9843868661D4A90005F66D043B48E1C362AF39C3C5F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029462Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:55.273{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com62473-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029461Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:57.163{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F3AC85D28044374ED57C09AF8787145B,SHA256=4E54AFFEA3E6BCCAA113FBE02C82A19B07C0B7C79E352381F3D2FB975EE616B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041670Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:58.966{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=64CE5F7441C85CC043BD3A45133756D3,SHA256=37652770D9C5ED4393305CE1638C126CBE292175EF456A2B44374633C0157FFE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029464Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:58.991{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B31B3AB2B1BDB86D4FA9DCD56C59FB4,SHA256=DA70E62EE6856ECE5D8E3BD06A773AFD40668E2F06DED245D02A157218AC9931,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041671Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:59.966{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A3E9372619D9CD7A3C51486E3607F670,SHA256=762456576F621E810F4438508E3B497AE5A5A9AC19479EFC5DFF9F2497E11CF9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029467Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:59.991{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F99253F1FC78AB67E0CC770CB0BD56C0,SHA256=ECC06577819972C89149ED053DA8FCD3956222B0782893A61967797552452A75,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029466Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:59.788{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B77B09E49B7A5389F00F313E18091028,SHA256=A782A65B3423AE8D47A93196B8FE3C46139EE7CF3AC239A3B7A1529BF5428BBC,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029465Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:56.634{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51163-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041672Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:00.981{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C21351BB6C4ECE7092F4A44369887B09,SHA256=14D090AC8F5E1994088AC4D1106D668CED6B1DFD416C1FDF4C464686DB78BA91,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029468Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:40:57.884{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com62683-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029469Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:01.007{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1BD9917D665EFFB6DCE581350DB664C,SHA256=DBF3F2C10DC72D7B386533D06A517B4087F0B406ECD2E7665A29B76E0073A52E,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041673Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:40:59.104{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59027-false10.0.1.12-8000- 354300x800000000000000029472Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:00.239{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com62857-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029471Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:02.132{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=554019B1D748C9AF03BE0DB5BB8E38B5,SHA256=A1430402F2595FFB3E33EB425198B8FEF4E6AB98E303793BFF891552763DCE7A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029470Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:02.023{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=99460D37DBC35EB76EB20FE6DFA433B1,SHA256=E13010352DDA163AB901D12D64AEE885E483A64E8683372455DD9C40F73A11CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041675Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:02.700{8D4DD44E-5BA9-616D-1100-000000000402}372NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=38FCD9BD8E49294B131A19A6DA8A2F01,SHA256=DF5989AB277B04AA00EACB7BE3FC5B1B20C8631CA10A379C75DD399AFBBF1146,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041674Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:01.997{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4189ECCB4DBC987E47C5006B4964F06,SHA256=876D57FBB9596D8974DFB44434E90F6FEF9E0E64F79020FE0729434DD0EC8042,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041676Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:03.012{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D3ED6F754C883FA2E2C043D32F8E09EC,SHA256=DD1EEA6BC6D8D627D3337D8EBCE3B29CD7EB0459B7316A4FDBF2AAC08CDCAD25,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029474Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:03.976{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DECAD008B6308B457AF3401FFAB2F97B,SHA256=D88E4CA0F05DE79CF1A4CA2509450E4EFD4E506C9206CB3514743D819302C3F3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029473Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:03.023{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F789E6DD1D25FBD0CC213D2FACB18D2F,SHA256=6072DFCD5CEC2EF96638A1AAB56C959398C2367545356F69F7DC6FF657389CE0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041677Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:04.028{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2D113D64E12A37F5430B1CAACC5AFA6D,SHA256=0CEEEA2946EB21A17E63E1F234226F94DB3C95EC2C3DCC7AAE29193D7BB954CA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029477Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:02.023{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com62996-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029476Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:01.650{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51164-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029475Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:04.069{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC0F26D1ECD2C9341991F55BDCEBE3B0,SHA256=CAB94DF8AD5630259094EE1D5DB1385A142BC8C8B22838EB4B72904C80C2425D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041678Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:05.059{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1423C09DEF128B482283A1E0880CB7C,SHA256=C8F35CACA474A24D7E27BEF9F4D83C151FEF516161C2E248D21024F7E3F4B953,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029478Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:05.101{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FDE200FCD5DD3F86E6B1B4BF57B57A4E,SHA256=7DDF81BA3D61885BD2D878DFF86154F0DD3FD4EC9462A0130A00D62A2661F05F,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029481Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:04.364{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com63180-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029480Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:06.257{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E5F1C9F5966EED16324F27C9877E0282,SHA256=9C445B6353436F2F4B8921CA54F89A0668758A71F33634092D6CD54C2FCFCA1B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029479Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:06.132{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F2CC64534397C93E8F1D479537AF8D2,SHA256=481165EDBD911AF883197D562CB66B69667C7048CA9E45C030FA2711900D5906,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041693Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:05.089{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59028-false10.0.1.12-8000- 10341000x800000000000000041692Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7972-616D-1B09-000000000402}4576C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041691Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041690Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041689Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041688Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041687Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041686Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041685Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041684Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041683Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041682Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7972-616D-1B09-000000000402}4576C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041681Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.340{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7972-616D-1B09-000000000402}4576C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041680Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.341{8D4DD44E-7972-616D-1B09-000000000402}4576C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041679Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:06.184{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=22EA3923B7ABA3FB1766253B0BA2CD20,SHA256=52E5FAC64F8E795BE2D4A8FEA1E90361A0A81B4C44DECABE52E3D5FDA8F29C0B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041724Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.775{8D4DD44E-5C1E-616D-A400-000000000402}2432NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041723Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.712{8D4DD44E-7973-616D-1D09-000000000402}1964512C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041722Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7973-616D-1D09-000000000402}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041721Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041720Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041719Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041718Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041717Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041716Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041715Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041714Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041713Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041712Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7973-616D-1D09-000000000402}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041711Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.509{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7973-616D-1D09-000000000402}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041710Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.510{8D4DD44E-7973-616D-1D09-000000000402}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041709Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.431{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D7B963DDC9F4A98878B02C6C488E7360,SHA256=F23127C266C1EC308C25836728B070C1EFDE749EAA14D2CAF7FA7B3D4E6E1AE0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041708Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.431{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BE89EADC41DF2638B15C29C58D12E17A,SHA256=4D42D59B288EBB525DCE05F6C136B1246B0EC922D5E9A527D9B6119A61F5CD50,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041707Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.275{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3D491C921717F3EF14373B6413D2637,SHA256=58F892A298E9F478502142DB67A5D9283E1DDDF93A5FA8075FAE400617964BC3,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029482Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:07.172{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=559085D79C97F2F00DF5E9B040CA0DE8,SHA256=876828DD627F12363D1CC4F503C00CE4479F14B8608EA855F0272390D833C079,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041706Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7973-616D-1C09-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041705Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041704Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041703Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041702Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041701Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041700Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041699Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041698Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041697Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041696Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-7973-616D-1C09-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041695Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7973-616D-1C09-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041694Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.009{8D4DD44E-7973-616D-1C09-000000000402}3040C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041740Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.665{8D4DD44E-7974-616D-1E09-000000000402}42964892C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041739Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.556{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D7B963DDC9F4A98878B02C6C488E7360,SHA256=F23127C266C1EC308C25836728B070C1EFDE749EAA14D2CAF7FA7B3D4E6E1AE0,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041738Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7974-616D-1E09-000000000402}4296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041737Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041736Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041735Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041734Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041733Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041732Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041731Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041730Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041729Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041728Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7974-616D-1E09-000000000402}4296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041727Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.493{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7974-616D-1E09-000000000402}4296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041726Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.494{8D4DD44E-7974-616D-1E09-000000000402}4296C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041725Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:08.431{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C3B1DBA6802121E14A4350390AE4E72,SHA256=6D91AF466CD93A780FE5C1E45673D7C2CDEB1C1E10E551AD981B47D6C96DAACE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029489Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:08.906{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db\snapshot.old\snap.datMD5=0C79A0BC7DD5E5813495446D6231C188,SHA256=086836619A019167957BEC23B6AFCF558395DF1AA21E8AA5FCEEA13ED738F1C2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029488Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:08.906{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db\snapshot.old\btree_records.datMD5=B57951F64E627F60EF244F33319EE755,SHA256=CA6E843723B094A2EF6C984E032847CA5CA2991B0615F0E7BF4018E001158358,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029487Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:08.906{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db\snapshot.old\btree_index.datMD5=D266805817E4DAD912452C6A3FFFA5D0,SHA256=1921C716EB08767D8922BFEE2ED4643513CB7F2EAED1A54CAC6369A969F8BD0D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029486Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:06.089{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com63320-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029485Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:08.406{6F8252D3-5E51-616D-A600-000000000502}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=710EA7B05D6BA2B04E69371F5A9F9563,SHA256=075ECC83A1E933E764EAFADBAEB274EC261ADF2B116F7C6E9B011B23E81CE501,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029484Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:08.187{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9AB208BC48658A49FE6CBD2A03EC5711,SHA256=067C26A53DFCFF70BD50279EBFF220E998452EC76FF5874F23CB1EED7181470B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029483Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:08.000{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5798F9D2BD9ADCE67615BD00FE3070E3,SHA256=94A5E1389A72244D3B4D7DA87EE4151E23A0427A1222E6E0B770B9B6162144E3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041769Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7975-616D-2009-000000000402}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041768Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041767Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041766Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041765Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041764Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041763Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041762Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041761Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041760Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041759Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-7975-616D-2009-000000000402}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041758Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.946{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7975-616D-2009-000000000402}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041757Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.948{8D4DD44E-7975-616D-2009-000000000402}3844C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x800000000000000041756Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.681{8D4DD44E-7975-616D-1F09-000000000402}50084848C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 354300x800000000000000041755Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:07.632{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59029-false10.0.1.12-8089- 23542300x800000000000000041754Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ADE503059E86ACBE3F41AB66FB6B2A43,SHA256=214424871EDF8DE2A28D8A61BE88B5629DD495F7DC533679DC8033279B91A720,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041753Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7975-616D-1F09-000000000402}5008C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041752Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041751Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041750Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041749Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041748Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041747Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041746Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041745Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041744Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041743Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7975-616D-1F09-000000000402}5008C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041742Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.446{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7975-616D-1F09-000000000402}5008C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041741Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:09.447{8D4DD44E-7975-616D-1F09-000000000402}5008C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000029493Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:07.939{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51166-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8089- 354300x800000000000000029492Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:07.893{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com63466-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029491Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:06.723{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51165-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029490Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:09.187{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=95FB9698251A15A8063F1A7833819F52,SHA256=F05D3976F0E522B3AEE5A35A2B6D8B33B6FB56E12735C3530BA00A154975935F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041772Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:10.915{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5480873BB91460A038AFEC9A6B0B7455,SHA256=3E1B4178A04B31D1DB8B6D664D12759EA69C19BD8B899CD6DFCB89EFA66A7C57,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041771Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:10.915{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D51A6DB5D2C2067874476540919B8B7D,SHA256=8EE3F21D6FF201B749EA2617F6EEF0289606457AD59034B79E16FD2F25D05096,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029495Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:10.218{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3DDCB0EDE220D39B1B54F386F5194BC,SHA256=A665D5D7290CA8896AA6DC43612D8D8AC77BCC60F29056A5558A22BC850B353C,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041770Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:10.212{8D4DD44E-7975-616D-2009-000000000402}38444464C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029494Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:10.171{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6A2BA2BD1AE19CA6BED97C60F0A641D9,SHA256=036F071885C13F28174AF7216CEF6F2317A197C128CA470FDF778DE84442A1AB,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041786Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5C1E-616D-A800-000000000402}8723676C:\Windows\system32\conhost.exe{8D4DD44E-7977-616D-2109-000000000402}4728C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041785Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041784Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041783Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041782Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041781Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041780Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041779Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041778Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041777Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041776Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-7977-616D-2109-000000000402}4728C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041775Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.962{8D4DD44E-5C1E-616D-A400-000000000402}24323524C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{8D4DD44E-7977-616D-2109-000000000402}4728C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041774Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.963{8D4DD44E-7977-616D-2109-000000000402}4728C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{8D4DD44E-5C1E-616D-A400-000000000402}2432C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041773Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.931{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CF0726371BD53590A241C31EF701758C,SHA256=544BB20E1F68F5F2EFBDF3BDF7440FE5CD07ABE927F8BEDBAA92D28247A20ED2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029496Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:11.234{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B07DF658CE7F94E226AB2C16FED658E,SHA256=FC0461F871FD8211FB02645EF2B33B2AE46F7599F570B5A27596E9A5C125C306,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041787Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:12.962{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BECAA33468C26A8E2A341FE2820598B6,SHA256=A94CB17F450D166A7EA1DC93406B68AEA036BA862CBD462EBBC5819E6EE2B610,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029499Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:10.226{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com63638-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029498Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:12.296{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2117D9DE08995EB749974A75800ABDE1,SHA256=F7CA075FC62913A0BDA1892995AE67FF3001B9C9D94F741995974271D91C0E1C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029497Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:12.140{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=99DB2B1EA66C95FED88C616FFF4B416F,SHA256=38FD4B328580857D860E6D3D04A8DE8925AD60E7544BEDFB25398708CAB2DA73,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029500Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:13.312{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A64DF56EF9728F5C6A16454D3A429F2D,SHA256=7E14F7741829ADCFDFBC004285D50805F16F8BB7780E9F452A9366F5525BEC14,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041789Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:11.054{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59030-false10.0.1.12-8000- 23542300x800000000000000041788Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:13.009{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E16F5F5028063879381304A43182DCC7,SHA256=406661825266560AFEAB9FF1074FF665B5D013FDDDD9F4320B0EBF445DBE8FC3,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029504Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:12.720{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51167-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000029503Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:12.632{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com63830-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029502Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:14.531{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A60E395EC0309EFFA2E9DD9E9D778F0F,SHA256=5CC702575558B0BC28A387F4B1FF1AB7256C962F63D44DFD34D0A6F5E5B3F51F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029501Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:14.359{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6E41ABCC2FCB9C587D4250252C81F0B3,SHA256=2200D6991E3F03C3C99731E180F5AFE5569313A85C28806FA528376A149C378A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041790Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:14.150{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D6D9CF20970F5822473FD45130AA4502,SHA256=7AD612420717352BD95335BBB1FAD1BD95D1E283450CCE9B60B972B04CDA6E20,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041791Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:15.165{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02CA53F43EE6BF4D2DE4C0FE97EE82A3,SHA256=D8E568C6A06060B3BAE5247289DB54C2EA266FA9B5EAE8906A813402FBD5D9DC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029505Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:15.375{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4E4AE1EB5C3125CB348C420EE191C34,SHA256=17AE7C52E296678940D8317C1EAB3AAEFFF6CBE4D09C32F932A48A1FC82D2D8F,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041792Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:16.259{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5D83315EDA433A519681AB63D708827D,SHA256=5B2E8C206F80D6D83CAEC6CFBFCEFF3306D35642D23816CB870D245134579B9D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029507Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:16.421{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D258D4F1ABFA1F195E200C6E09552635,SHA256=79C486A35A7DC0DF245735C56B6C6FC32930A8B813D987B8029CECCF5A03EA2D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029506Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:16.296{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=153819DB5C1F83A0EB2BEA5262550B73,SHA256=B803DD1BBAE65311B0ADB9EFD60354F8873C5035AFE62232800DDB5EF6B29CD0,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041793Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:17.337{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7A14B71FA9C67A82658AB49FD9548832,SHA256=0F7CC1E0942B5A752C194721E71E9AFFDDD39EC88FC4692626FBE1E8B31C314A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029509Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:17.422{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0DC6CE8B5EF3A1C504F2A0651A1726F5,SHA256=3F81211688E89F05B8E4DF49EB9A857DE2A7E301A31D42959C5EB4A6B44E1BBB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029508Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:14.396{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com63965-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041794Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:18.556{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B7F9DAFC86AAB6A1B4F8CC61A5B96836,SHA256=9296B67F67B9F58B221C120E8FED3AC314FD605E5A056BD89B8959E90E7FF877,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029512Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:16.551{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com64138-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029511Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:18.500{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDFC57BB13F9EC3B9D3E2FF6517C3B58,SHA256=0546C28329AD143727482A8899B225538DD73C5FD2A39EC92ACD21CCB235C942,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029510Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:18.437{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E2B4EE9305B931E9733915BD122E606A,SHA256=41CAD6643E173ED25E7E028EAFC5F2233881277524727AEFFDBC2D32FD7AC6D8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029513Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:19.515{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE8AFA5A863ED2C7121419B54ECA0DF4,SHA256=B75858AC13304778ABB085A728EC0BEB6C7EF1D7481698DA6745C22E227107CE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041796Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:19.587{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCAB0905A86DE31A67899265A1599DBD,SHA256=0D74B23946CCADE6AC78E3044A97D9ACEE5B0EB4F88470B7130DD3AD94056C86,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041795Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:17.038{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59031-false10.0.1.12-8000- 23542300x800000000000000041797Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:20.587{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C89E4B45F0F98D1E9DB6A2C212AC1C4E,SHA256=29ACF85B77A524BD02048731CA9F1720DF36552E43194C9BBAA4AE0C81646FB8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029517Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:20.968{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0BE4A59EC287BD3E607B920A2F5D8215,SHA256=63FC1A553779610C90DC6EB167BA00D133DBC43EA63F4A4599E8117E0B3960F4,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029516Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:19.065{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com64330-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029515Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:18.688{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51168-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029514Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:20.531{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=13CA038DF22856A11A58A1DB6C5A3E63,SHA256=2BDCD4CC13DED7195DC7D4AB8BE4B7A0B6B2C63BE6BF9B12CCBF31591327C211,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041798Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:21.603{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67C0AE1EB7F0A18CCC118EFBF6590D44,SHA256=6F1208988828534CC8A7464970C03B940EB8AB9145F88C723AF77C2CDA77B8F4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029518Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:21.546{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=479D68ABEAAC11139C46CB0AF336FC1F,SHA256=C9889763C76878E1E29B4D5A5CF26BFF61B3BCE3B3BA58C85E569212490199FF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041799Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:22.618{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C38FDC81FE70FDF3746EB8929FCC32F,SHA256=0C964326C53FB760741ECE2996734692BA17B54DACC3893E2356A2D75050832C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029520Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:22.750{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2486FA6CCF63630102B66EFE026664CB,SHA256=1B593BA8FD4D9A20C0E35EFA808E0985C290D6ADA8B347330F1E0D72ACAE4A21,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029519Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:22.562{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=72458596161B45DF6A3A76D15F90D9C8,SHA256=670AF86B6F831CD88930F650C00F8B31D6EA555F3A82746B636AC6B3C12BA988,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029522Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:23.578{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8FF34FADD02068283A45DC036CDAA5A9,SHA256=06A3477B2AEDFF809E1CEE228B6674094C78C3E6C7F36EE0E080357D50816B12,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041800Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:23.649{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05973E80379633D3E76ED62DFD7F32EE,SHA256=045169DA2B142E003FA727C83B14AB1B34652CDD2928584B374DF1748DF55ABB,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029521Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:20.850{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com64475-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029524Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:24.937{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B85F03DB5C196C0CFEE04949CA184078,SHA256=D2A47A611D74B6D7ED055C866431F226251FE545EDFB83041EA80D78F0B92D05,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029523Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:24.640{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F268007FB9CCE3EA1304D7740D0853F,SHA256=67096EDB2C5D5D03BC165C3C590AEF7A64060D163D4EAE84AD2800C84B7533B8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041802Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:24.696{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11CB723523BA2E7E82688BD783A0B279,SHA256=66CBFE9FB8CE3042312750E4D54D161899AB9E181D24CC70F0D386CA78B5B7B5,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041801Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:22.069{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59032-false10.0.1.12-8000- 23542300x800000000000000041803Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:25.743{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=342C434089B8ADEB9A628E325E14C75B,SHA256=DC9CF56CF985311B213BA5E802D6EFA814DACEC42E8AE62E5FD9189A4CBA6F62,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029526Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:25.671{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6384D0E865BB41F631B9F02C6C98C869,SHA256=B2603D7612CF61730CA6CBFF8788CACB11AB1E5DB66EBC26E88081DB86C2D599,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029525Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:22.993{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com64652-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041804Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:26.790{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E954EC33D879D91271EDEAA1468CAA79,SHA256=2449FDE3C68308B3E675DDE7DBFD55FF418C68EEE3C6502FF4717192C6FADA4E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029529Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:26.843{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=212D55F73EE0A847CC6737AF7EACD4AC,SHA256=B6F5BD4F1943948A0E621E083DBCD8DC9C1E992AADEA5E1827838F40FDCD89CC,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029528Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:26.703{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=698412D5D532F71C47367AE40E0C3150,SHA256=2A7046EA410FDBC678D573B3C5A5F195E8FDC68599FFE2D7FE35AD09E0D8880C,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029527Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:23.782{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51169-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000041805Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:27.936{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BFFF5C3A0FBF7FFE9DFE4FC91F8CA897,SHA256=A89B6805C87A0C8CE1122D9734D0EF033286C56FF15B8BABA9917513772DD6BD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029531Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:27.706{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=56BFE9DB47AE581DA0CDB52030530BDC,SHA256=A7E2AA90004E5974A02716120FB7D547B48A1214DC4A66DB8D7934AEEC714F44,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029530Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:24.956{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com64794-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000041807Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:28.947{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C83C1103A58E7E0DA1E8E5963BEB6ABB,SHA256=8E4B9950FF5A58673D22A108D8434C652EF6346D9F9BD8F9969E5BAC37886301,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029532Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:28.721{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E1EAF6703030CEB74F8A09A8D8136B3,SHA256=857A4FEB2EA6DD931FAD517B6DC3977A814C1D487DC8041F520EB93BFE23AA45,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041806Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:28.427{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\respondent-20211018113419-123MD5=8D93873C901538A8B2B909297EDAE7BB,SHA256=9423023AAA5D37B26F7EE3576993D2852CE2F95EF8E5E497C042A8474DDD26FD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041809Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:29.980{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=13FBE31E9B4D6E8F126AFAAFAFC9A346,SHA256=2F445DFA0AB76DFA29762D1AB336E6CC9E55A8A43A36837747105326F2A86536,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029535Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:29.737{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E0060F2213EFD1320FDDD02FC883A66,SHA256=97737897EC2276AB891ADD382A5B7F3FC6EC02F2F5820C3E9EEBFAD7A0AD29C9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041808Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:29.433{8D4DD44E-5BB9-616D-2900-000000000402}2880NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-05dcb7a5482346836\channels\health\surveyor-20211018113417-124MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029534Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:29.112{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9229C7D713A3290645EC4DCA1D628CCC,SHA256=96403415E27CEAA5B667501166B28607254EE9917FE1E0387FBBCCEDB0ECE152,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029533Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:27.180{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com64952-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029536Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:30.753{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6FD40DC923EC7CDFB808C47D2D7405FE,SHA256=8A860074E3B1CBC43F8B97C9C2ED95DF205775B71D4464060328A6A6F8765434,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041810Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:27.965{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59033-false10.0.1.12-8000- 10341000x800000000000000029565Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-798B-616D-E206-000000000502}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029564Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029563Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029562Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029561Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029560Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029559Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029558Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029557Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029556Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029555Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-798B-616D-E206-000000000502}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029554Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.971{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-798B-616D-E206-000000000502}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029553Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.972{6F8252D3-798B-616D-E206-000000000502}212C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029552Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.768{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4CF309C20B0BE71A5E8D7CE8A41C02E8,SHA256=5B4B307D38A4D24D67E4C2F9AA10B144ED71686B6F83DA33286701D59C8F6C57,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041811Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:31.011{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E4650540B23C6FFAA540BD608C795F5,SHA256=14F654D919F120463FDB280ADB1705B6FFD5FE51B02F6D7DEAFD4B55270537C3,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029551Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-798B-616D-E106-000000000502}3968C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029550Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029549Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029548Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029547Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029546Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029545Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029544Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029543Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029542Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029541Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5DB9-616D-0500-000000000502}412428C:\Windows\system32\csrss.exe{6F8252D3-798B-616D-E106-000000000502}3968C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029540Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.471{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-798B-616D-E106-000000000502}3968C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029539Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.472{6F8252D3-798B-616D-E106-000000000502}3968C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029538Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.253{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D8A638452604D8F93ABCF01B1490864A,SHA256=C0C3460F0B044EE42857680CF661EB6851A47A69BAF2119F5C19181D3F5FBD90,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029537Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:29.357{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com65134-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029582Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.815{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=528ED5E2E2605BF251F7EB618F068E8B,SHA256=814F0A9B8C85EF87D7CE2D9A92CB81D756EF8D017D709028066F41CCD2613C7E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041812Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:32.246{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=52ACA5CE05FBB4143A4614873021C1FD,SHA256=B12036D397E4C5CB37C315B0B75FC471C7613F49ABC4A53A2327E916A2874912,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029581Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.659{6F8252D3-798C-616D-E306-000000000502}39043412C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029580Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-798C-616D-E306-000000000502}3904C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029579Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0F67785739E7C9B6EA31C0CED4AA36C9,SHA256=A2EAD1715C14696AFFC38AB2D9AA85C1350FB0DDB231272AD380F4A1264BE1F8,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029578Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029577Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029576Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029575Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029574Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029573Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029572Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029571Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029570Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029569Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-798C-616D-E306-000000000502}3904C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029568Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.487{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-798C-616D-E306-000000000502}3904C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029567Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:32.488{6F8252D3-798C-616D-E306-000000000502}3904C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000029566Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:29.722{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51170-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029598Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.909{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3A5AFE7757A662CE1B5EFE6E206ACD17,SHA256=5B735BA9AF4034D8CBA6F7B0E1F4586D740EC0A3BC0C32C38E053F2E5E163168,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041815Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:33.371{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A9C4F654CB5D269A9056EA948666F3DC,SHA256=7D51E75E32C0337D3932FB80BF72A84C6F59BE00FE2A1ED09512E57DA4D4E0D2,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029597Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.690{6F8252D3-798D-616D-E406-000000000502}3388216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029596Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-798D-616D-E406-000000000502}3388C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029595Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029594Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029593Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029592Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029591Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029590Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029589Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029588Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029587Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029586Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-798D-616D-E406-000000000502}3388C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029585Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-798D-616D-E406-000000000502}3388C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029584Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.534{6F8252D3-798D-616D-E406-000000000502}3388C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029583Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.518{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E50046E9CCF7653C729D1472C367E631,SHA256=3FA21B7C017C15122C229B580A1CB1B95E0CCEE9D50D174ED7A941F8929F6DFF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041814Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:33.121{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FEEB9A8D8825A382B6811D5437C97BF4,SHA256=54C19D14225CF2573B32F03399C45DE4E5318DCA8C35D500BA3C269189E41D5B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041813Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:33.121{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=510F98F7F37552E6907219B314EE2AE1,SHA256=9B597C21641FFA93F0E4E347B175BE2BB257072754B4601BE0380E8C308164D4,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029614Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.924{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FFBB45D1131AAD27EF6327865B84AB7E,SHA256=216979C64B02A0A68C73FA01CD60398D353142DA4E043EBF8FEC75BFF0295A02,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041818Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:34.386{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5A5BD8871E2322216E51197DB5ED275,SHA256=69167A998BACB0CE6D2A4B164075D4B56BBE26B6171C121EB3F3A05914AA4E54,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029613Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-798E-616D-E506-000000000502}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029612Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029611Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029610Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029609Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029608Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029607Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029606Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029605Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029604Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029603Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-798E-616D-E506-000000000502}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029602Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-798E-616D-E506-000000000502}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029601Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.753{6F8252D3-798E-616D-E506-000000000502}2872C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000029600Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:34.581{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=517C799E05488247BB47BBFD53976237,SHA256=4B007BF78AC90A31F2C40E20BFF2DC78F6C0A983CF53CFC4A31492814E89B7FA,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029599Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:31.927{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com65337-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000041817Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:31.978{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local59034-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 354300x800000000000000041816Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:31.978{8D4DD44E-5BB9-616D-2C00-000000000402}3020C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-185.attackrange.local59034-true0:0:0:0:0:0:0:1win-dc-185.attackrange.local389ldap 23542300x800000000000000029631Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.971{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=442BE1ADC8E071DAA803E044F3B440F3,SHA256=492CA6DEA8BD1AB9E46B28808A8345BADF36603480CDA756A0882FFD6B8AE4B2,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041820Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:35.402{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36CBBC862EE434907B1CC060B526B7E8,SHA256=9470A36D8E690E259580CC2F8EFDD6B8F266DE1FC259C9835718987C0E5F49D8,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041819Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:33.056{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59035-false10.0.1.12-8000- 23542300x800000000000000029630Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.690{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C95FD338C0D13AE8349053FDB2497116,SHA256=AB1C72FA99ACC80099800043D811663CCE5EDDD0EDEA6457A0B5A7419E7025F9,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029629Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.596{6F8252D3-798F-616D-E606-000000000502}996856C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029628Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-798F-616D-E606-000000000502}996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029627Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029626Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029625Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029624Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029623Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029622Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029621Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029620Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029619Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029618Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5DB9-616D-0500-000000000502}412968C:\Windows\system32\csrss.exe{6F8252D3-798F-616D-E606-000000000502}996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029617Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.424{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-798F-616D-E606-000000000502}996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029616Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.425{6F8252D3-798F-616D-E606-000000000502}996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 354300x800000000000000029615Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:33.777{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com65484-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029646Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.987{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A24CC84337267A834A1FBDA0C947655,SHA256=8E00FC276C247FD5CDC88C5CB53711F850A90625B4CD3103D0516F4C5BB3E5B5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041821Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:36.417{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=410DF56827591426C456BBBD015030B0,SHA256=6F7910A6F194E87D3302911C77387A1F38F4AF6B0404C29357FA3879110887A4,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000029645Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.289{6F8252D3-7990-616D-E706-000000000502}992632C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029644Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5E52-616D-AA00-000000000502}38403052C:\Windows\system32\conhost.exe{6F8252D3-7990-616D-E706-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029643Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029642Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029641Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029640Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029639Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029638Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029637Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029636Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029635Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0C00-000000000502}7281708C:\Windows\system32\svchost.exe{6F8252D3-5DBB-616D-1C00-000000000502}1992C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000029634Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5DB9-616D-0500-000000000502}412528C:\Windows\system32\csrss.exe{6F8252D3-7990-616D-E706-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000029633Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.081{6F8252D3-5E51-616D-A600-000000000502}32642512C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{6F8252D3-7990-616D-E706-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000029632Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:36.082{6F8252D3-7990-616D-E706-000000000502}992C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{6F8252D3-5DB9-616D-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{6F8252D3-5E51-616D-A600-000000000502}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 23542300x800000000000000041822Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:37.605{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=57BA5A520A92A9CB96408EC218B13B4C,SHA256=0AFC1019DE3CB171672D7AF70CF8FC3E1E4C22B89AE798B7DA1D3F213CC1CB6D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029649Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.629{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com49256-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 354300x800000000000000029648Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:35.629{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51171-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 23542300x800000000000000029647Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:37.081{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E157762E97388B95CA4A3CCA27F4BD30,SHA256=CDD4B5FB20862DA221502009A4334BDFED2E158979E34D07BC1DB52062E4A4CA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041823Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:38.683{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=96628B100F9990A1EED0A4AA5BA85701,SHA256=DD474DA5D51FD9CEC91CDB86B51379F87E7260203D694D7088E9EA46A54430D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029650Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:38.003{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4787B98930EED3A1DF17DDFD270BB7B6,SHA256=68B3ABF1B619FDE14A7C6531E2EAA03D83105FF3BF9F043475E3E16BDD28B735,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041825Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:39.699{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8633E3864CD960E346E79C6465E04DB6,SHA256=84E984367C2B6BD9731546D6B2E35D85C880032EF229FE5D2A7FE179D27D2451,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029652Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:39.972{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DB3D74DED7D0A34EF2BD20D9BE888A22,SHA256=270B210C0E4F24552796C65F56708498F32FD2B800A4FE1856F69E3501253BD8,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029651Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:39.049{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=809CEA944CC3201565528B84DB5EE48D,SHA256=6A3FB4B554DC09B14B581EFB8F83076B34DF7E9AF72C889B1C235C29C0064210,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041824Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:38.118{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59036-false10.0.1.12-8000- 23542300x800000000000000041826Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:40.730{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84CF7B5A98716780BA752DF10660E75C,SHA256=9B4C2CDD2C186F1DD2A8714115C387EA2B97F025195E0B2FBF7311589B1411FD,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029654Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:38.023{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com49457-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029653Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:40.065{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C2D60962CE9ACB66AC3B3BC23420DC9,SHA256=16347DF2C9F575981D43FADC00F6638F4D7D2C36BF13DD1811001347922FFF09,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041827Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:41.761{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DD890F4DC80878188447CB06530378BC,SHA256=A4455502AE8F050BB90A8449E0CF971C79587126A0DA4EB265AAEAD84160652C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029655Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:41.096{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A12516D2975BEFBD536088B2CE54C39,SHA256=48EF6D438149D0463169867168593A05A38DCE09203FDAAA10243DB9F449DE57,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041828Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:42.761{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1862C043843173F113152512A56125A0,SHA256=4727D7A879A7E6B414C2B3092B8E04F3E18178E32E0896298EB2EE8F9574C5D5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029659Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:42.721{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=76AEC3AC94DDF4EBE6DB929562E36016,SHA256=71F18911BA8C7B23CAE5968179BE18EDDCE170099DBBE2F98723B1D0351EAFB2,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029658Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:40.785{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51172-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000029657Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:40.771{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com49649-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029656Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:42.112{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=378FB8C92376E63906384E1C73E43A3A,SHA256=8B85454E70F9E257F1CD32A02BACA15B7D1A19875C124A551B0700A8AAE63B3E,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041829Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:43.777{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=485ECDC99B16ED6A31D500DA63DD38FD,SHA256=BBC87DEA7DA7FF00D3514604BFD8C82F3D126F406BFEF4E64A9A8C32891793D9,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029660Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:43.128{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9EEBDCF119CEFBC724A5AC031E7E39AA,SHA256=1A8149637A6466973DB670F336A5C6A456B59DD06ED995D140DBCB0C709CA2AE,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041831Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:44.808{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6D4AF52E28E9C6B0427B0CA5B09E3454,SHA256=03B4DBF5723C1294A7D15E416A86283FBA8C6EB0DECBBE36524F7E59A7547B8D,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029663Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:42.671{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com49786-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029662Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:44.596{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C4BA50AB79E2A8E721F6F442BB9D838E,SHA256=7405452A62F329A2EC13E803EE710F5917C7BE10392690A2AFBF855BDA8CEFEF,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029661Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:44.175{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DDE75DBC9169C77A84EE8BF7E9FC1211,SHA256=D276FDE6DE07C273B11E5CBD80EF2C48B77A46A80B16246990E159CB53E94526,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041830Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:43.134{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59037-false10.0.1.12-8000- 23542300x800000000000000041832Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:45.839{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5817FC6B51AF6FA2CE9192BC001C47DD,SHA256=1C2AECE99466DFF843105473A90BB77BD0BF4F49BA58286FF271105F462D3A15,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029664Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:45.206{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02FE8494488D51E2F1E6E58587CB51AA,SHA256=4E422E01B81BC9E6BE344E852FD3E5DD42DD29C7224DD12E8455B41247C42669,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041833Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:46.871{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98F394A38DE08496F686F5BB2E1D2596,SHA256=C170E69815694084B48817031FB8DC332DE4D0F31393FB97DBF44AD37717676A,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029667Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:44.546{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com49938-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029666Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:46.487{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B4C2ADB0C8DB1A6D62F9630330DAB802,SHA256=F9E6DF1F531D7B9E1D47613490BFDE6F24B320E7840C7E0B5845C5A621293092,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029665Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:46.221{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=19418C9180C4DCD394F29EDE956B7497,SHA256=C6B725B5393652F97575F9439BCD7D057E935395B3234E884314A023A7A18A23,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041835Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:47.903{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F41DA122F04C7D11C5059D4B9BCF98D,SHA256=D9CF7A6AB9FCACA6BB059EB0128FA68DA7423179F70BC9B019D0A5A91C7AE912,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000041834Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:46.057{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse18.169.157.221ec2-18-169-157-221.eu-west-2.compute.amazonaws.com21345-false10.0.1.14win-dc-185.attackrange.local3389ms-wbt-server 23542300x800000000000000029668Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:47.237{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C67ACA450C1E595EA6B87C0D0C81F5F3,SHA256=B35792E4906CEBCD0AFED2652F32955FA54BC245F61CBBA1B60EEBAD97247F67,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041836Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:48.935{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FBB287D53FDE8396E60BAC3667FA1067,SHA256=425A4D8925B6775099C82A58D5E6CECDE1EACAC4690EA8DDD707C74698034352,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029672Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:46.644{6F8252D3-5E5A-616D-D400-000000000502}652C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-470.attackrange.local51173-false10.0.1.12ip-10-0-1-12.eu-central-1.compute.internal8000- 354300x800000000000000029671Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:46.349{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com50073-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029670Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:48.268{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85EFD22BB0AAD06A45F28E7128A27C1B,SHA256=411E4353EC2F25934402FD62A20805804E0FF86569C0D8EA10C564829A1B0819,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029669Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:48.237{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=541A25264BBB2E20B23DD0082E92F5D6,SHA256=0878E37A457C792633D1F08B9C4E3587B708BBDEEA581CA8FF4848DA5FD0ACFD,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041838Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:49.966{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D00A6BC6CEB36C568EE5483DC222B6E5,SHA256=EA6934A7DF0C037FA85DF94D2A647476C0945881FEC6FEDF47C1BD21FA5D4D00,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029673Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:49.284{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=17681C95C2EABED42282EE69D983D792,SHA256=8E5D7BA3FF2696EA33033F8D178E2FB9AB2724354B985FF3BA85D75B54B46B94,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041837Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:49.903{8D4DD44E-5BA9-616D-1400-000000000402}10684888C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\cryptsvc.dll+6124|c:\windows\system32\cryptsvc.dll+5e34|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 354300x800000000000000029677Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:48.832{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com50273-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029676Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:50.735{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B38BE4A20A052C206926662E1A32EB3A,SHA256=7C9F926C25564C1A1084E123922C47236E2AAAD49CBD97C36BACAE906EC2702B,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029675Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:50.297{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5395FAB53F9D7F212A2B425B6CC66B6,SHA256=6AD33EEBCD94CA4FA746222F661CEF6E26470093737A8907B31EBC2ED3381375,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029674Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:50.165{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\respondent-20211018114253-115MD5=2CB5601F5EDCA21E63E0E40ACBE3ABA7,SHA256=0D77ED474202710A0E95D2759556AB1551A681C71D327764AEA259A6D67A6999,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029680Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:51.861{6F8252D3-5DBA-616D-1300-000000000502}300NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=8D7C7A446E469857F85A92EB5E57ADA5,SHA256=B103ECEF27C273D6AB3DDD81B5725A3686307165402791300810A9F30813FA19,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029679Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:51.327{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB8FFAFE8981B953D3ACEB493A8B6478,SHA256=1B634409F334C2B98FC4CA7A0B25D165294EC3CF68431E2D8867B61EF5300F61,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000041897Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\mouclass\Enum\NextInstanceDWORD (0x00000002) 13241300x800000000000000041896Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\mouclass\Enum\CountDWORD (0x00000002) 13241300x800000000000000041895Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\mouclass\Enum\1TERMINPUT_BUS\UMB\2&2c22bcc9&0&Session2Mouse0 13241300x800000000000000041894Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\terminpt\Enum\NextInstanceDWORD (0x00000002) 13241300x800000000000000041893Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\terminpt\Enum\CountDWORD (0x00000002) 13241300x800000000000000041892Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\terminpt\Enum\1TERMINPUT_BUS\UMB\2&2c22bcc9&0&Session2Mouse0 13241300x800000000000000041891Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localInvDB-DriverVerSetValue2021-10-18 13:41:51.794{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Control\Class\{4d36e96f-e325-11ce-bfc1-08002be10318}\0002\DriverVersion10.0.14393.0 13241300x800000000000000041890Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\kbdclass\Enum\NextInstanceDWORD (0x00000002) 13241300x800000000000000041889Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\kbdclass\Enum\CountDWORD (0x00000002) 13241300x800000000000000041888Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\kbdclass\Enum\1TERMINPUT_BUS\UMB\2&2c22bcc9&0&Session2Keyboard0 13241300x800000000000000041887Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\terminpt\Enum\NextInstanceDWORD (0x00000001) 13241300x800000000000000041886Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\terminpt\Enum\CountDWORD (0x00000001) 13241300x800000000000000041885Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Services\terminpt\Enum\0TERMINPUT_BUS\UMB\2&2c22bcc9&0&Session2Keyboard0 13241300x800000000000000041884Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localInvDB-DriverVerSetValue2021-10-18 13:41:51.778{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Control\Class\{4d36e96b-e325-11ce-bfc1-08002be10318}\0002\DriverVersion10.0.14393.0 23542300x800000000000000041883Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.622{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F9BC301FE581BB13E5DB907A48F092E,SHA256=7F59AC7D4990FC3B58A0B41D1CD20A492E31F72ACD4DA6F777D88A26C16D6F5D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041882Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.528{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+2387f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041881Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.528{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+2380c|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041880Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.528{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+237c4|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041879Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041878Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041877Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041876Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041875Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041874Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041873Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041872Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041871Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041870Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2309-000000000402}3768C:\Windows\system32\csrss.exe0x101000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+1ac1c|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e 10341000x800000000000000041869Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1abf6|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e 10341000x800000000000000041868Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+1abdc|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e 10341000x800000000000000041867Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-799F-616D-2209-000000000402}49402904C:\Windows\System32\smss.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\SYSTEM32\ntdll.dll+8c64e|C:\Windows\SYSTEM32\ntdll.dll+8c3f9|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+2042|\SystemRoot\System32\smss.exe+1d5e|\SystemRoot\System32\smss.exe+1b09|\SystemRoot\System32\smss.exe+14cb|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+5179f 154100x800000000000000041866Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.503{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\System32\winlogon.exe10.0.14393.3204 (rs1_release.190830-1500)Windows Logon ApplicationMicrosoft® Windows® Operating SystemMicrosoft CorporationWINLOGON.EXEwinlogon.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e72SystemMD5=DEA4CE12F24601830083126E18A2C7C9,SHA256=F002F8C2EA49D21F242996E3D57F5FDD7995FE6DB524BB69BBD7F190CC0211A9,IMPHASH=3CF10D94C117DB4F6E9D523B93429D6D{8D4DD44E-799F-616D-2209-000000000402}4940C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 000000b8 0000007c 10341000x800000000000000041865Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA4-616D-0200-000000000402}3204064C:\Windows\System32\smss.exe{8D4DD44E-799F-616D-2309-000000000402}3768C:\Windows\system32\csrss.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6cd4|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+1d401|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041864Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.497{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2309-000000000402}3768C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+1a7a4|c:\windows\system32\lsm.dll+1aa31|C:\Windows\SYSTEM32\ntdll.dll+1d401|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041863Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041862Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041861Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041860Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041859Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041858Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041857Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041856Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041855Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041854Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-799F-616D-2209-000000000402}49402904C:\Windows\System32\smss.exe{8D4DD44E-799F-616D-2309-000000000402}3768C:\Windows\system32\csrss.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\SYSTEM32\ntdll.dll+8c64e|C:\Windows\SYSTEM32\ntdll.dll+8c3f9|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+1ee4|\SystemRoot\System32\smss.exe+20a1|\SystemRoot\System32\smss.exe+1c92|\SystemRoot\System32\smss.exe+1af6|\SystemRoot\System32\smss.exe+14cb|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+5179f 154100x800000000000000041853Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.482{8D4DD44E-799F-616D-2309-000000000402}3768C:\Windows\System32\csrss.exe10.0.14393.2969 (rs1_release.190503-1820)Client Server Runtime ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationCSRSS.Exe%%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e72SystemMD5=955E9227AA30A08B7465C109B863B886,SHA256=D896480BC8523FAD3AE152C81A2B572022C3778A34A6D85E089D150A68E9165E,IMPHASH=273BC9D936389D79244E6E56BE5096B6{8D4DD44E-799F-616D-2209-000000000402}4940C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 000000b8 0000007c 10341000x800000000000000041852Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA4-616D-0200-000000000402}3204064C:\Windows\System32\smss.exe{8D4DD44E-799F-616D-2209-000000000402}4940C:\Windows\System32\smss.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6cd4|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+1d401|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041851Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041850Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041849Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041848Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041847Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041846Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041845Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041844Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041843Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041842Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.466{8D4DD44E-5BA4-616D-0200-000000000402}320960C:\Windows\System32\smss.exe{8D4DD44E-799F-616D-2209-000000000402}4940C:\Windows\System32\smss.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\SYSTEM32\ntdll.dll+8c64e|C:\Windows\SYSTEM32\ntdll.dll+8c3f9|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+2042|\SystemRoot\System32\smss.exe+36ee|\SystemRoot\System32\smss.exe+3c31|C:\Windows\SYSTEM32\ntdll.dll+1d401|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\SYSTEM32\ntdll.dll+5179f 154100x800000000000000041841Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:51.471{8D4DD44E-799F-616D-2209-000000000402}4940C:\Windows\System32\smss.exe10.0.14393.2969 (rs1_release.190503-1820)Windows Session ManagerMicrosoft® Windows® Operating SystemMicrosoft Corporationsmss.exe\SystemRoot\System32\smss.exe 000000b8 0000007c C:\Windows\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e72SystemMD5=725EC50D4B0F607BF5B45B5E0115770B,SHA256=56881BCAEAC350107A6453F38F020FE0E284DBE2E8A6F37ED482985E0DD98EA7,IMPHASH=09DDECA5943933973FE7DDDD24ED724A{8D4DD44E-5BA4-616D-0200-000000000402}320C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 354300x800000000000000041840Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:49.104{8D4DD44E-5C25-616D-D200-000000000402}2624C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-185.attackrange.local59038-false10.0.1.12-8000- 23542300x800000000000000041839Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:50.997{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=90130DF168DF50C2E764E658CCB4711C,SHA256=4659F3A0CEE39680999B6EB30B0E05478FAE807338FE31C1BF4A0D2C0AD29AD5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029678Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:51.173{6F8252D3-5DBB-616D-1A00-000000000502}1924NT AUTHORITY\SYSTEMC:\Program Files\Amazon\SSM\amazon-ssm-agent.exeC:\ProgramData\Amazon\SSM\InstanceData\i-0bbc1b6cc737a83c0\channels\health\surveyor-20211018114251-116MD5=97EF2A570B75C4F95FC69B0D09A2E2A2,SHA256=11396EA313B0ED7E3228C4FA92ABE9D836DB8F416A7A8A28ACC77133025082E7,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000029683Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:50.522{6F8252D3-5DBA-616D-1000-000000000502}952C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse198.46.199.161198-46-199-161-host.colocrossing.com50399-false10.0.1.15win-host-470.attackrange.local3389ms-wbt-server 23542300x800000000000000029682Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:52.424{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C4D130FE1C6C62B5FBA7BFB65EFD4F2D,SHA256=BBC8D8DCF84B3B7794195E101DBAC082DD9CE4361E30172DF6953947AEB61415,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029681Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:52.346{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27A753718080EF640292502101496AC4,SHA256=D3FD5476C4101B26793006B9C00A6BC844F93882597A948623EAA74759063F1B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041965Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.747{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+54c6|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041964Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.669{8D4DD44E-79A0-616D-2509-000000000402}26043652C:\Windows\system32\LogonUI.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\logoncontroller.dll+2eef5|C:\Windows\System32\RPCRT4.dll+48684|C:\Windows\System32\RPCRT4.dll+31850|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041963Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.669{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041962Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.669{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041961Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.653{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041960Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.653{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041959Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.653{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+54c6|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041958Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.591{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=0A587E83181F463FC744A71AAE0266BB,SHA256=B7C4973AFA5E96840B05659AD6489C8F2241F005214CCCCF4E23A43465EF2391,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041957Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.591{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=8C7B3BF0150F777CC244FF5BA03E7300,SHA256=98DE8C70FEA7D627A9CF0647581AE3C5BB3B6C7842DDAC1048405DDC6C93ED8D,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041956Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.497{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=8258471A3CFB642162C9443C7DEFCBB9,SHA256=E9EB3F631EFC6F918451C4E16BF11DC150F1C18D59F0B9FBEBC03E99E3B8231A,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041955Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.482{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=FCACAECF7F5A6CFDC08AAEB044912D55,SHA256=8F1B830FD359226ABFD80CFC0F1481929361A92E3F2390CF019785FBA756D05D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041954Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.466{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041953Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.466{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041952Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.466{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041951Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.466{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041950Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.466{8D4DD44E-5BA9-616D-1600-000000000402}12921908C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041949Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.466{8D4DD44E-5BA9-616D-1600-000000000402}12921336C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041948Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.451{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=87F8256227DBA8C1A20D25A3C890C2C9,SHA256=51B54F2DDEF8D447C7DA61870AA6E9A123BE6B7B025028E1F3D3A0FE62387444,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041947Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.388{8D4DD44E-799F-616D-2309-000000000402}37684020C:\Windows\system32\csrss.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041946Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-799F-616D-2409-000000000402}4924708C:\Windows\system32\winlogon.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\SYSTEM32\dwminit.dll+2d11|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041945Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041944Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041943Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041942Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041941Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041940Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041939Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041938Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041937Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041936Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.384{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\System32\dwm.exe10.0.14393.0 (rs1_release.160715-1616)Desktop Window ManagerMicrosoft® Windows® Operating SystemMicrosoft Corporationdwm.exe"dwm.exe"C:\Windows\system32\Window Manager\DWM-2{8D4DD44E-79A0-616D-FFF7-500000000000}0x50f7ff2SystemMD5=C89F159A577F19F7F03C73C98D29D841,SHA256=B3E37997C1C62DD90D69EF83D6A6FC782BF9A5B8AD04A0D1528A8B7FA31AA408,IMPHASH=DDB7DE3741333EE031929A760FCD4542{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\System32\winlogon.exewinlogon.exe 10341000x800000000000000041935Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+10d7e|C:\Windows\system32\lsasrv.dll+1e088|C:\Windows\system32\lsasrv.dll+1d2b1|C:\Windows\system32\lsasrv.dll+1c000|C:\Windows\system32\lsasrv.dll+27f0b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041934Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+10d7e|C:\Windows\system32\lsasrv.dll+1e088|C:\Windows\system32\lsasrv.dll+1d2b1|C:\Windows\system32\lsasrv.dll+1bad0|C:\Windows\system32\lsasrv.dll+27f0b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041933Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+10d7e|C:\Windows\system32\lsasrv.dll+1a4b6|C:\Windows\system32\lsasrv.dll+1ba5f|C:\Windows\system32\lsasrv.dll+27f0b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041932Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.357{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041931Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.357{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041930Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.357{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041929Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.357{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000041928Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.341{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CAC797094E890847468046AAC411F2BD,SHA256=95209CA0A72C72885DDB0DEE71F91863D3B8E00D9B2FF4D3D67366ECC1785493,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000041927Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.341{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FEEB9A8D8825A382B6811D5437C97BF4,SHA256=54C19D14225CF2573B32F03399C45DE4E5318DCA8C35D500BA3C269189E41D5B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000041926Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.310{8D4DD44E-5BA9-616D-1600-000000000402}12924292C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041925Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.310{8D4DD44E-5BA9-616D-1600-000000000402}12921336C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041924Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.278{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041923Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.278{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041922Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041921Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041920Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041919Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041918Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041917Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041916Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041915Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041914Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041913Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041912Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-799F-616D-2309-000000000402}37684020C:\Windows\system32\csrss.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000041911Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+1b02d|C:\Windows\system32\lsasrv.dll+27f0b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041910Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041909Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-799F-616D-2409-000000000402}49241268C:\Windows\system32\winlogon.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\winlogon.exe+193b7|C:\Windows\system32\winlogon.exe+22617|C:\Windows\system32\winlogon.exe+2b287|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000041908Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.273{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\System32\LogonUI.exe10.0.14393.0 (rs1_release.160715-1616)Windows Logon User Interface HostMicrosoft® Windows® Operating SystemMicrosoft Corporationlogonui.exe"LogonUI.exe" /flags:0x2 /state0:0xa3a6e855 /state1:0x41c64e6dC:\Windows\system32\NT AUTHORITY\SYSTEM{8D4DD44E-5BA7-616D-E703-000000000000}0x3e72SystemMD5=B38DFCF985D8AE5B1A17C264981E61C7,SHA256=AA62D29803D52EC06CD27ED3124E034048F09606EB7342181913C9817C7B44C5,IMPHASH=A6F3A84D171E55B51A7343E05C8DFAC3{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\System32\winlogon.exewinlogon.exe 10341000x800000000000000041907Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041906Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041905Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041904Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA9-616D-1600-000000000402}12924292C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041903Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA9-616D-1600-000000000402}12924292C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+4689|c:\windows\system32\themeservice.dll+3fdd|c:\windows\system32\themeservice.dll+3c53|c:\windows\system32\themeservice.dll+2675|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041902Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.263{8D4DD44E-5BA9-616D-1600-000000000402}12921336C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041901Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.247{8D4DD44E-5BA9-616D-1600-000000000402}12924292C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x147aC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\themeservice.dll+3de3|c:\windows\system32\themeservice.dll+26c0|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041900Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.247{8D4DD44E-5BA9-616D-1600-000000000402}12921336C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041899Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.107{8D4DD44E-799F-616D-2309-000000000402}37684284C:\Windows\system32\csrss.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\winsrv.DLL+1ef0|C:\Windows\system32\winsrv.DLL+17e9|C:\Windows\system32\winsrv.DLL+1579|C:\Windows\SYSTEM32\ntdll.dll+5179f 23542300x800000000000000041898Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:52.028{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=341A21A26F6AE488D78BD2C9C4F0F268,SHA256=7CB299A4F83E6E9393D8C5F96ABC360150D8E59D49EC2E92EB388B5DD83906A7,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029684Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:53.377{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8752E452C58179AC6C1D5D0E5BE58A0,SHA256=CDACCA592005A0529B339FA1AADE65B91C91F225CA108DEE308633BB0D424C37,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042130Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-799F-616D-2309-000000000402}37683740C:\Windows\system32\csrss.exe{8D4DD44E-79A1-616D-2809-000000000402}4752C:\Windows\system32\efsui.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042129Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8481700C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042128Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8481700C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042127Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8481700C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042126Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042125Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042124Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042123Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042122Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042121Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042120Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042119Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042118Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042117Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-79A1-616D-2809-000000000402}4752C:\Windows\system32\efsui.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042116Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042115Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042114Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA6-616D-0B00-000000000402}628660C:\Windows\system32\lsass.exe{8D4DD44E-79A1-616D-2809-000000000402}4752C:\Windows\system32\efsui.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\SYSTEM32\efsext.dll+2d2c|C:\Windows\system32\EFSCORE.dll+18451|C:\Windows\system32\EFSCORE.dll+17c2a|C:\Windows\system32\EFSCORE.dll+17805|C:\Windows\system32\EFSCORE.dll+18bd|C:\Windows\system32\efssvc.dll+1337|C:\Windows\System32\sechost.dll+b71a|C:\Windows\System32\sechost.dll+a574|C:\Windows\system32\lsasrv.dll+544be|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000042113Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.990{8D4DD44E-79A1-616D-2809-000000000402}4752C:\Windows\System32\efsui.exe10.0.14393.0 (rs1_release.160715-1616)EFS UI ApplicationMicrosoft® Windows® Operating SystemMicrosoft Corporationefsui.exeefsui.exe /efs /installdraC:\Windows\system32\ATTACKRANGE\Administrator{8D4DD44E-79A1-616D-927B-510000000000}0x517b922HighMD5=6DFA1BBB4D2F89DC46BACABC83B6AB95,SHA256=1106CE6AE6EDFFA752D71F5EFF9FAAB53360CFFC6B224957760FBDC0A7D4FF17,IMPHASH=B865E978ADDB9A939A91896A60E81464{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeC:\Windows\system32\lsass.exe 10341000x800000000000000042112Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+773d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042111Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042110Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|c:\windows\system32\lsm.dll+23c29|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042109Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042108Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+23c18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042107Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|c:\windows\system32\lsm.dll+1fc37|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042106Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1fb39|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042105Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042104Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042103Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+773d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042102Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042101Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+23e0b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042100Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042099Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042098Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042097Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042096Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+f290|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042095Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+f290|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042094Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+37c3|c:\windows\system32\SYSNTFY.dll+1dcb|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49e88|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042093Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.982{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+48684|C:\Windows\System32\RPCRT4.dll+31850|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042092Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.919{8D4DD44E-79A0-616D-2509-000000000402}2604NT AUTHORITY\SYSTEMC:\Windows\system32\LogonUI.exeC:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\1033\StructuredQuerySchema.binMD5=E871053170AD09568882637D049295DC,SHA256=CEA9EABB0B46AC602CDC3FB6FE6215981F2D7C0C6A5C5023CE72860232DBE12B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042091Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.903{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042090Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.903{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042089Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.903{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042088Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.857{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C57F1DABF1E4918D7D2F6DBA0B69F4E4,SHA256=627E1E4D5A99B39CE366570098AADDCF35655CE5BFA83E502EC1137C0F212693,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042087Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.794{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042086Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.794{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042085Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.794{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042084Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042083Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042082Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042081Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042080Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042079Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042078Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.778{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042077Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.747{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A1-616D-2709-000000000402}1340C:\Windows\system32\DllHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+54c6|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042076Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.732{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-79A1-616D-2709-000000000402}1340C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042075Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.732{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A1-616D-2709-000000000402}1340C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+366e9|c:\windows\system32\rpcss.dll+3bed2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042074Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.669{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+10d7e|C:\Windows\system32\lsasrv.dll+1fb5a|C:\Windows\SYSTEM32\samsrv.dll+5e81|C:\Windows\SYSTEM32\samsrv.dll+5d82|C:\Windows\SYSTEM32\samsrv.dll+158ce|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042073Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042072Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042071Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+626ce|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042070Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+6267d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042069Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA9-616D-1600-000000000402}12924292C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+48684|C:\Windows\System32\RPCRT4.dll+31850|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042068Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+5b40|c:\windows\system32\lsm.dll+2de4|c:\windows\system32\lsm.dll+57af|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042067Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+2dce|c:\windows\system32\lsm.dll+57af|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042066Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.638{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+5b40|c:\windows\system32\lsm.dll+5f9d|c:\windows\system32\lsm.dll+57a4|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042065Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.622{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+f290|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042064Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.622{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+f290|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042063Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+f290|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042062Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+5b40|c:\windows\system32\lsm.dll+2f9b|c:\windows\system32\lsm.dll+5727|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042061Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+2f4d|c:\windows\system32\lsm.dll+5727|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042060Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+5b40|c:\windows\system32\lsm.dll+5f9d|c:\windows\system32\lsm.dll+5718|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042059Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+56c4|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042058Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1a375|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042057Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042056Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042055Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.607{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1a375|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042054Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.591{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042053Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.591{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042052Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.591{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 13241300x800000000000000042051Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localContext,DeviceConntectedOrUpdatedSetValue2021-10-18 13:41:53.591{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Enum\SWD\ScDeviceEnumBus\1\FriendlyNameMicrosoft Passport Container Enumeration Bus 13241300x800000000000000042050Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localInvDB-DriverVerSetValue2021-10-18 13:41:53.591{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}\0003\DriverVersion10.0.14393.0 23542300x800000000000000042049Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.497{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3B679DCC1D55C4FC4FC8D570C58C340,SHA256=34182707107D40D714704141B82140159C104B5BAAB61609575F169E0432A658,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042048Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.435{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042047Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.435{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042046Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.435{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042045Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.435{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042044Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.435{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+10d7e|C:\Windows\system32\lsasrv.dll+1e088|C:\Windows\system32\lsasrv.dll+1d2b1|C:\Windows\system32\lsasrv.dll+1bad0|C:\Windows\system32\lsasrv.dll+27f0b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042043Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.435{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+10d7e|C:\Windows\system32\lsasrv.dll+1a4b6|C:\Windows\system32\lsasrv.dll+1ba5f|C:\Windows\system32\lsasrv.dll+27f0b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 13241300x800000000000000042042Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localContext,DeviceConntectedOrUpdatedSetValue2021-10-18 13:41:53.435{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Enum\SWD\ScDeviceEnumBus\0\FriendlyNameSmart Card Device Enumeration Bus 13241300x800000000000000042041Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localInvDB-DriverVerSetValue2021-10-18 13:41:53.435{8D4DD44E-5BA4-616D-0100-000000000402}4SystemHKLM\System\CurrentControlSet\Control\Class\{62f9c741-b25a-46ce-b54c-9bccce08b6f2}\0002\DriverVersion10.0.14393.0 10341000x800000000000000042040Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042039Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042038Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042037Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042036Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042035Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042034Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042033Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.419{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042032Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.403{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042031Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.403{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+773d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042030Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042029Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|c:\windows\system32\lsm.dll+23c29|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042028Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042027Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+23c18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042026Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|c:\windows\system32\lsm.dll+1fc37|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042025Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1fb39|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042024Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042023Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042022Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+773d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042021Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA9-616D-0F00-000000000402}3082740C:\Windows\System32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\termsrv.dll+a1297|c:\windows\system32\termsrv.dll+6aab8|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042020Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042019Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042018Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042017Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042016Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.388{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CAC797094E890847468046AAC411F2BD,SHA256=95209CA0A72C72885DDB0DEE71F91863D3B8E00D9B2FF4D3D67366ECC1785493,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042015Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042014Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042013Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042012Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042011Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\lsasrv.dll+25aa7|C:\Windows\system32\lsasrv.dll+26bed|C:\Windows\system32\lsasrv.dll+25925|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042010Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA6-616D-0B00-000000000402}6284720C:\Windows\system32\lsass.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\lsasrv.dll+2586d|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042009Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA9-616D-0F00-000000000402}3082740C:\Windows\System32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\termsrv.dll+a1297|c:\windows\system32\termsrv.dll+6aab8|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042008Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042007Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.372{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042006Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.247{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BC7551EC38472B3D6340A33D5C7A2DC9,SHA256=F3D36DFD26ECE5DBFD497AC9FA6B6E2290695F3BA58EEAFED68AA5118F87D2A5,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000042005Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.247{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1190706B523DA8B7EFBEA81375693C23,SHA256=A2DC63091901AC7C0129A1C2844FD990AB842F23CBF73DCC865373D938EE6657,IMPHASH=00000000000000000000000000000000falsetrue 354300x800000000000000042004Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:49.713{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse93.104.66.206ppp-93-104-66-206.dynamic.mnet-online.de53856-false10.0.1.14win-dc-185.attackrange.local3389ms-wbt-server 10341000x800000000000000042003Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA9-616D-1000-000000000402}4961776C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cd4|c:\windows\system32\fntcache.dll+17a6f|c:\windows\system32\fntcache.dll+1a637|c:\windows\system32\fntcache.dll+1aa6c|c:\windows\system32\fntcache.dll+501de|c:\windows\system32\fntcache.dll+4fee2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042002Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1700-000000000402}1404C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+6a63|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042001Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+626ce|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000042000Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+6267d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000041999Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-ConnectPipe2021-10-18 13:41:53.107{8D4DD44E-5BA9-616D-0F00-000000000402}308\TSVCPIPE-4780db3a-6839-41e2-a307-96878a690e87C:\Windows\System32\svchost.exe 10341000x800000000000000041998Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+157b1|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041997Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1f3a|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041996Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.107{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1439d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 18141800x800000000000000041995Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-ConnectPipe2021-10-18 13:41:53.091{8D4DD44E-5BA9-616D-0F00-000000000402}308\TSVCPIPE-4780db3a-6839-41e2-a307-96878a690e87C:\Windows\System32\svchost.exe 18141800x800000000000000041994Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-ConnectPipe2021-10-18 13:41:53.075{8D4DD44E-5BA9-616D-0F00-000000000402}308\TSVCPIPE-4780db3a-6839-41e2-a307-96878a690e87C:\Windows\System32\svchost.exe 10341000x800000000000000041993Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+626ce|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x800000000000000041992Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-0F00-000000000402}308C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+6267d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+61899|C:\Windows\System32\combase.dll+1279|C:\Windows\System32\combase.dll+3b24c|C:\Windows\System32\combase.dll+3af02|C:\Windows\System32\combase.dll+39818|C:\Windows\System32\combase.dll+3757d|C:\Windows\System32\combase.dll+36c4f|C:\Windows\System32\combase.dll+52489|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49cee|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 18141800x800000000000000041991Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-ConnectPipe2021-10-18 13:41:53.075{8D4DD44E-5BA9-616D-0F00-000000000402}308\TSVCPIPE-4780db3a-6839-41e2-a307-96878a690e87C:\Windows\System32\svchost.exe 17141700x800000000000000041990Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-CreatePipe2021-10-18 13:41:53.075{8D4DD44E-5BA9-616D-0F00-000000000402}308\TSVCPIPE-4780db3a-6839-41e2-a307-96878a690e87C:\Windows\System32\svchost.exe 10341000x800000000000000041989Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041988Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1200-000000000402}784C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041987Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2500-000000000402}2776C:\Windows\System32\spoolsv.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041986Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041985Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA9-616D-0F00-000000000402}3081880C:\Windows\System32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\termsrv.dll+a1297|c:\windows\system32\termsrv.dll+6a79d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041984Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041983Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041982Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.075{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1400-000000000402}1068C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041981Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA9-616D-1600-000000000402}12921416C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x147aC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\themeservice.dll+3de3|c:\windows\system32\themeservice.dll+26c0|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041980Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041979Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA9-616D-1600-000000000402}12921336C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041978Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041977Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041976Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041975Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d6162|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041974Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041973Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}8484312C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041972Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+396a|c:\windows\system32\SYSNTFY.dll+1fc3|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49e88|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041971Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+48684|C:\Windows\System32\RPCRT4.dll+31850|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041970Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA6-616D-0B00-000000000402}628840C:\Windows\system32\lsass.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+48684|C:\Windows\System32\RPCRT4.dll+31850|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041969Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA9-616D-1600-000000000402}12921416C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+48684|C:\Windows\System32\RPCRT4.dll+31850|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041968Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA9-616D-1000-000000000402}4961776C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cd4|c:\windows\system32\fntcache.dll+17a6f|c:\windows\system32\fntcache.dll+1a637|c:\windows\system32\fntcache.dll+1aa6c|c:\windows\system32\fntcache.dll+501de|c:\windows\system32\fntcache.dll+4fee2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041967Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA9-616D-1000-000000000402}4961776C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cd4|c:\windows\system32\fntcache.dll+17a6f|c:\windows\system32\fntcache.dll+1a637|c:\windows\system32\fntcache.dll+1aa6c|c:\windows\system32\fntcache.dll+501de|c:\windows\system32\fntcache.dll+4fee2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000041966Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.060{8D4DD44E-5BA9-616D-1000-000000000402}4961776C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2509-000000000402}2604C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6cd4|c:\windows\system32\fntcache.dll+17a6f|c:\windows\system32\fntcache.dll+1a637|c:\windows\system32\fntcache.dll+1aa6c|c:\windows\system32\fntcache.dll+501de|c:\windows\system32\fntcache.dll+4fee2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000029686Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:54.611{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BF95017C81D1496F3C419D0C9752B398,SHA256=1133AC077AE4EE42DB95045827B7069AE95A60D9A0D989673FB8DAA1EAD70102,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000029685Microsoft-Windows-Sysmon/Operationalwin-host-470.attackrange.local-2021-10-18 13:41:54.408{6F8252D3-5E60-616D-DD00-000000000502}2892NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E00E0F15E69DC89C009DD606107A08BE,SHA256=387F6B2FA0F76C69AE4CA5BB12DE69A9E624BDF60067F86D97D8FE73A77E41D5,IMPHASH=00000000000000000000000000000000falsetrue 13241300x800000000000000042377Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.982{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\NTDS\Parameters\ldapserverintegrityDWORD (0x00000001) 13241300x800000000000000042376Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.982{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\Netlogon\Parameters\requiresignorsealDWORD (0x00000001) 13241300x800000000000000042375Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.982{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\LanmanServer\Parameters\requiresecuritysignatureDWORD (0x00000001) 13241300x800000000000000042374Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.982{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\LanmanServer\Parameters\enablesecuritysignatureDWORD (0x00000001) 13241300x800000000000000042373Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1101SetValue2021-10-18 13:41:54.982{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Control\Lsa\nolmhashDWORD (0x00000001) 354300x800000000000000042372Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.662{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59040-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local49666- 354300x800000000000000042371Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.662{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59040-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local49666- 354300x800000000000000042370Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.661{8D4DD44E-5BA9-616D-0D00-000000000402}904C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59039-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 354300x800000000000000042369Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:53.661{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local59039-truefe80:0:0:0:499a:5ff5:cd3f:fbdewin-dc-185.attackrange.local135epmap 10341000x800000000000000042368Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.888{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042367Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.888{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042366Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.888{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042365Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.888{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042364Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.888{8D4DD44E-799F-616D-2309-000000000402}37683632C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-3409-000000000402}5036C:\Windows\Explorer.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042363Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.888{8D4DD44E-79A2-616D-3309-000000000402}51004740C:\Windows\system32\userinit.exe{8D4DD44E-79A2-616D-3409-000000000402}5036C:\Windows\Explorer.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\userinit.exe+1cd8|C:\Windows\system32\userinit.exe+23e5|C:\Windows\system32\userinit.exe+346e|C:\Windows\system32\userinit.exe+3725|C:\Windows\system32\userinit.exe+4553|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000042362Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.718{8D4DD44E-79A2-616D-3409-000000000402}5036C:\Windows\explorer.exe10.0.14393.4169 (rs1_release.210107-1130)Windows ExplorerMicrosoft® Windows® Operating SystemMicrosoft CorporationEXPLORER.EXEC:\Windows\Explorer.EXEC:\Windows\system32\ATTACKRANGE\Administrator{8D4DD44E-79A1-616D-927B-510000000000}0x517b922HighMD5=F7FDECA990692D53D7E4E396B0BD711E,SHA256=1F955612E7DB9BB037751A89DAE78DFAF03D7C1BCC62DF2EF019F6CFE6D1BBA7,IMPHASH=8D2880102609AA4B23679BD4FEBEBC95{8D4DD44E-79A2-616D-3309-000000000402}5100C:\Windows\System32\userinit.exeC:\Windows\system32\userinit.exe 734700x800000000000000042361Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.060{8D4DD44E-79A1-616D-2809-000000000402}4752C:\Windows\System32\efsui.exeC:\Windows\System32\cryptdll.dll10.0.14393.2969 (rs1_release.190503-1820)Cryptography ManagerMicrosoft® Windows® Operating SystemMicrosoft Corporationcryptdll.dllMD5=4B31902F1E0B79CE7E46D9877647C1CC,SHA256=8925892119315293C49D09A26191149660934BF1E5D3D023722E90339ADA38AA,IMPHASH=CAB6D6025DF08B0D0BC6259D625E2778trueMicrosoft WindowsValid 23542300x800000000000000042360Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.700{8D4DD44E-5BA9-616D-1600-000000000402}1292NT AUTHORITY\SYSTEMC:\Windows\system32\svchost.exeC:\Windows\security\templates\policies\tmpgptfl.infMD5=F443C7B00E42C58336E9113C4B92A1EA,SHA256=01406B7BD612A8321213382482E44EA2C7B5467B57E17E9C135EAB2A8221FAEA,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000042359Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.685{8D4DD44E-5BA9-616D-1600-000000000402}1292NT AUTHORITY\SYSTEMC:\Windows\system32\svchost.exeC:\Windows\security\templates\policies\tmpgptfl.infMD5=26FFB2926F32F78EAEF80D8A870A88C6,SHA256=BA4E44773C9233D16C9950097A1D1FEF3AB2E8376120959E529DC97EF1871D7C,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000042358Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.685{8D4DD44E-5BA9-616D-1600-000000000402}1292NT AUTHORITY\SYSTEMC:\Windows\system32\svchost.exeC:\Windows\security\templates\policies\gpt00001.infMD5=DBBF697C05F302D06DD05403297DB608,SHA256=632CAD193E30E450B7753E6D16643B576DFABAA1FA60E8D29DA7665946810599,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000042357Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.685{8D4DD44E-5BA9-616D-1600-000000000402}1292NT AUTHORITY\SYSTEMC:\Windows\system32\svchost.exeC:\Windows\security\templates\policies\gpt00000.domMD5=338F5A9E4E606FC803055C8314E3F366,SHA256=DD15D6AD575AD10CBA979783EE68DC6A5A21ECDABDB4E0678F83870931BBD317,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042356Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.653{8D4DD44E-5BA9-616D-1600-000000000402}12922312C:\Windows\system32\svchost.exe{8D4DD44E-79A2-616D-3309-000000000402}5100C:\Windows\system32\userinit.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39d09|C:\Windows\SYSTEM32\ntdll.dll+1e89a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042355Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.653{8D4DD44E-5BA9-616D-1600-000000000402}12921336C:\Windows\system32\svchost.exe{8D4DD44E-79A2-616D-3309-000000000402}5100C:\Windows\system32\userinit.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6144|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042354Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.653{8D4DD44E-5BA6-616D-0B00-000000000402}6284360C:\Windows\system32\lsass.exe{8D4DD44E-5BA4-616D-0100-000000000402}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96ef2|C:\Windows\system32\kerberos.DLL+793e4|C:\Windows\system32\kerberos.DLL+1443f|C:\Windows\system32\lsasrv.dll+2e0d1|C:\Windows\system32\lsasrv.dll+2c294|C:\Windows\system32\lsasrv.dll+31345|C:\Windows\system32\lsasrv.dll+2f1db|C:\Windows\system32\lsasrv.dll+2e0d1|C:\Windows\system32\lsasrv.dll+16cad|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e 10341000x800000000000000042353Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042352Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042351Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042350Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042349Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-799F-616D-2309-000000000402}37684020C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-3309-000000000402}5100C:\Windows\system32\userinit.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042348Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-799F-616D-2409-000000000402}49243648C:\Windows\system32\winlogon.exe{8D4DD44E-79A2-616D-3309-000000000402}5100C:\Windows\system32\userinit.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\winlogon.exe+15b13|C:\Windows\system32\winlogon.exe+ea76|C:\Windows\system32\winlogon.exe+b12f|C:\Windows\SYSTEM32\ntdll.dll+2064e|C:\Windows\SYSTEM32\ntdll.dll+1e864|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 154100x800000000000000042347Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.598{8D4DD44E-79A2-616D-3309-000000000402}5100C:\Windows\System32\userinit.exe10.0.14393.0 (rs1_release.160715-1616)Userinit Logon ApplicationMicrosoft® Windows® Operating SystemMicrosoft CorporationUSERINIT.EXEC:\Windows\system32\userinit.exeC:\Windows\system32\ATTACKRANGE\Administrator{8D4DD44E-79A1-616D-927B-510000000000}0x517b922HighMD5=C1B1FFC800BE2F31EB2CF8CB40629C69,SHA256=CFC6A18FC8FE7447ECD491345A32F0F10208F114B70A0E9D1CD72F6070D5B36F,IMPHASH=BFA137B16F3492AFCA0551687B067C04{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\System32\winlogon.exewinlogon.exe 10341000x800000000000000042346Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.591{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 13241300x800000000000000042345Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.544{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\EFS\StartDWORD (0x00000003) 23542300x800000000000000042344Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.497{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=89BB5BC45DE69DDBE437FD8819072631,SHA256=09628A39F236B6B1BE32570A9EFF49B4B5F11FDCC7D2714BB662BA8DC6B5375D,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042343Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042342Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042341Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+3a1a|c:\windows\system32\SYSNTFY.dll+1e8d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49e88|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042340Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.482{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042339Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.466{8D4DD44E-5BA9-616D-1600-000000000402}12921908C:\Windows\system32\svchost.exe{8D4DD44E-799F-616D-2409-000000000402}4924C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\sessenv.dll+3de88|c:\windows\system32\sessenv.dll+f881|c:\windows\system32\sessenv.dll+677c|c:\windows\system32\SYSNTFY.dll+1e8d|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49e88|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042338Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.450{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=545CB1CDFCE287C272AFB0E5284AC1DD,SHA256=4B3C9B13CB4431BC18DC05EFFC305EB5CCBDD6C336D21EC5891A02BB82E6E365,IMPHASH=00000000000000000000000000000000falsetrue 23542300x800000000000000042337Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.450{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=0A587E83181F463FC744A71AAE0266BB,SHA256=B7C4973AFA5E96840B05659AD6489C8F2241F005214CCCCF4E23A43465EF2391,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042336Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.435{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042335Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.419{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042334Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.310{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CDC386D04DA9C4AA8F88330805109B77,SHA256=C074299E1E937054BAF2399DA8AEB665D8ED8A2F694C676D34540841AADDE402,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042333Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.278{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA6-616D-0B00-000000000402}628C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 23542300x800000000000000042332Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.263{8D4DD44E-5C2B-616D-DB00-000000000402}3152NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B6B3BD263DDE4A931380647B63FC7A3,SHA256=7A3C762A6EE8578B1ACC23D08D268D7E750325707159A18147135E57CB4A7E2B,IMPHASH=00000000000000000000000000000000falsetrue 10341000x800000000000000042331Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.247{8D4DD44E-799F-616D-2309-000000000402}37684020C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-3209-000000000402}5024C:\Windows\system32\ServerManagerLauncher.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042330Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042329Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042328Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042327Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042326Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-79A2-616D-3009-000000000402}22444832C:\Windows\system32\conhost.exe{8D4DD44E-79A2-616D-2E09-000000000402}2576C:\Windows\System32\XblGameSaveTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\SYSTEM32\ConhostV2.dll+5ca7|C:\Windows\SYSTEM32\ConhostV2.dll+774b|C:\Windows\SYSTEM32\ConhostV2.dll+a8ef|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042325Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042324Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042323Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042322Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.232{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042321Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.216{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-3209-000000000402}5024C:\Windows\system32\ServerManagerLauncher.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042320Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.216{8D4DD44E-5BA9-616D-1600-000000000402}12921908C:\Windows\system32\svchost.exe{8D4DD44E-79A2-616D-3209-000000000402}5024C:\Windows\system32\ServerManagerLauncher.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\UBPM.dll+acf0|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+108c6|c:\windows\system32\UBPM.dll+d439|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+e9dd|c:\windows\system32\UBPM.dll+e1ba|c:\windows\system32\UBPM.dll+de12|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+36c9|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+65b65|C:\Windows\SYSTEM32\ntdll.dll+6586d|C:\Windows\SYSTEM32\ntdll.dll+656d0|C:\Windows\SYSTEM32\ntdll.dll+3a800|C:\Windows\SYSTEM32\ntdll.dll+1ed13|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042319Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.216{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042318Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.216{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042317Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.216{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042316Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.216{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042315Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA6-616D-0500-000000000402}412528C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-3009-000000000402}2244C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042314Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042313Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042312Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042311Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042310Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042309Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042308Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042307Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA6-616D-0500-000000000402}412428C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-2E09-000000000402}2576C:\Windows\System32\XblGameSaveTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042306Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA9-616D-1600-000000000402}12921908C:\Windows\system32\svchost.exe{8D4DD44E-79A2-616D-2E09-000000000402}2576C:\Windows\System32\XblGameSaveTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a7a1|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+d395|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+e9dd|c:\windows\system32\UBPM.dll+e1ba|c:\windows\system32\UBPM.dll+de12|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+36c9|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+65b65|C:\Windows\SYSTEM32\ntdll.dll+6586d|C:\Windows\SYSTEM32\ntdll.dll+656d0|C:\Windows\SYSTEM32\ntdll.dll+3a800|C:\Windows\SYSTEM32\ntdll.dll+1ed13|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042305Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042304Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042303Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1600-000000000402}1292C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042302Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BA9-616D-1700-000000000402}1404C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+6a63|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042301Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA6-616D-0A00-000000000402}620360C:\Windows\system32\services.exe{8D4DD44E-79A2-616D-2D09-000000000402}4520C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\System32\RPCRT4.dll+67d1f|C:\Windows\system32\services.exe+1713f|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042300Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.200{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-79A2-616D-2D09-000000000402}4520C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+54c6|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042299Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042298Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042297Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA8-616D-0C00-000000000402}8484372C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042296Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA8-616D-0C00-000000000402}8481920C:\Windows\system32\svchost.exe{8D4DD44E-79A0-616D-2609-000000000402}4548C:\Windows\system32\dwm.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042295Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-799F-616D-2309-000000000402}37683740C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-2D09-000000000402}4520C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cd4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042294Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042293Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA8-616D-0C00-000000000402}848352C:\Windows\system32\svchost.exe{8D4DD44E-5BB9-616D-2B00-000000000402}3008C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d3c|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51791 10341000x800000000000000042292Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0500-000000000402}412692C:\Windows\system32\csrss.exe{8D4DD44E-79A2-616D-2D09-000000000402}4520C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6144|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5179f 10341000x800000000000000042291Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}6202816C:\Windows\system32\services.exe{8D4DD44E-79A2-616D-2D09-000000000402}4520C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7414|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+307d|C:\Windows\system32\services.exe+6334|C:\Windows\system32\services.exe+dc24|C:\Windows\system32\services.exe+d248|C:\Windows\system32\services.exe+1dc37|C:\Windows\system32\services.exe+17f38|C:\Windows\System32\RPCRT4.dll+7a583|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653ea|C:\Windows\System32\RPCRT4.dll+4a284|C:\Windows\System32\RPCRT4.dll+4919d|C:\Windows\System32\RPCRT4.dll+49a4b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d35e|C:\Windows\SYSTEM32\ntdll.dll+1ecc9|C:\Windows\System32\KERNEL32.DLL+84d4 13241300x800000000000000042290Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\Description@%%SystemRoot%%\system32\WpnUserService.dll,-2 13241300x800000000000000042289Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\FailureActionsBinary Data 13241300x800000000000000042288Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\Security\SecurityBinary Data 13241300x800000000000000042287Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\DisplayNameWindows Push Notifications User Service_5208a3 13241300x800000000000000042286Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\ImagePathC:\Windows\system32\svchost.exe -k UnistackSvcGroup 13241300x800000000000000042285Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\ErrorControlDWORD (0x00000000) 13241300x800000000000000042284Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\StartDWORD (0x00000003) 13241300x800000000000000042283Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\WpnUserService_5208a3\TypeDWORD (0x000000e0) 13241300x800000000000000042282Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\Description@%%SystemRoot%%\system32\UserDataAccessRes.dll,-14000 13241300x800000000000000042281Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\FailureActionsBinary Data 13241300x800000000000000042280Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\Security\SecurityBinary Data 13241300x800000000000000042279Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\DisplayNameUser Data Access_5208a3 13241300x800000000000000042278Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\ImagePathC:\Windows\system32\svchost.exe -k UnistackSvcGroup 13241300x800000000000000042277Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\ErrorControlDWORD (0x00000000) 13241300x800000000000000042276Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\StartDWORD (0x00000003) 13241300x800000000000000042275Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UserDataSvc_5208a3\TypeDWORD (0x000000e0) 13241300x800000000000000042274Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\Description@%%SystemRoot%%\system32\UserDataAccessRes.dll,-10002 13241300x800000000000000042273Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\FailureActionsBinary Data 13241300x800000000000000042272Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\Security\SecurityBinary Data 13241300x800000000000000042271Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\DisplayNameUser Data Storage_5208a3 13241300x800000000000000042270Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\ImagePathC:\Windows\System32\svchost.exe -k UnistackSvcGroup 13241300x800000000000000042269Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\ErrorControlDWORD (0x00000000) 13241300x800000000000000042268Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\StartDWORD (0x00000003) 13241300x800000000000000042267Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\UnistoreSvc_5208a3\TypeDWORD (0x000000e0) 13241300x800000000000000042266Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\PimIndexMaintenanceSvc_5208a3\Description@%%SystemRoot%%\system32\UserDataAccessRes.dll,-15000 13241300x800000000000000042265Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\PimIndexMaintenanceSvc_5208a3\FailureActionsBinary Data 13241300x800000000000000042264Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\PimIndexMaintenanceSvc_5208a3\Security\SecurityBinary Data 13241300x800000000000000042263Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\PimIndexMaintenanceSvc_5208a3\DisplayNameContact Data_5208a3 13241300x800000000000000042262Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\PimIndexMaintenanceSvc_5208a3\ImagePathC:\Windows\system32\svchost.exe -k UnistackSvcGroup 13241300x800000000000000042261Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.local-SetValue2021-10-18 13:41:54.185{8D4DD44E-5BA6-616D-0A00-000000000402}620C:\Windows\system32\services.exeHKLM\System\CurrentControlSet\Services\PimIndexMaintenanceSvc_5208a3\ErrorControlDWORD (0x00000000) 13241300x800000000000000042260Microsoft-Windows-Sysmon/Operationalwin-dc-185.attackrange.localT1031,T1050SetValue2021-10-18 13:41:54.185