354300x8000000000000000221478Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:26.510{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-34446-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221479Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:27.630{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-42541-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221480Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:28.805{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-50558-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221481Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:29.968{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-58135-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221483Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:32.542{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17667-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221482Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:31.293{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-8015-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221484Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:33.826{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-25937-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221485Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:35.266{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-34864-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221486Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:36.510{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-43924-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221487Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:38.116{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53040-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221488Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:39.386{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2829-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221489Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:40.547{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11302-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221490Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:41.760{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-19363-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185707Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:38:41.683{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in37130-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221491Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:42.092{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in12514-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221492Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:43.164{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-28305-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221493Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:44.555{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-38128-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000221529Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221528Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221527Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221526Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221525Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221524Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221523Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221522Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221521Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221520Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221519Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221518Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221517Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221516Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221515Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221514Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221513Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221512Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221511Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221510Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221509Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221508Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221507Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221506Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221505Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221504Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221503Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221502Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221501Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221500Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221499Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221498Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221497Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221496Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221495Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221494Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:38:49.833{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000185708Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:38:46.484{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk1200-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221530Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:46.131{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-47537-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221532Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:47.492{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57427-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221531Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:46.721{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk14836-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185709Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:38:48.010{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse39.129.165.93-63105-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221533Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:48.570{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-6741-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221534Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:49.792{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-15244-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221535Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:51.009{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-22337-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221536Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:52.444{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-31612-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221537Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:53.696{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40610-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221538Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:55.133{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-49923-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221539Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:56.400{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-59733-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221540Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:57.481{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9272-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221542Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:59.868{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-24964-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221541Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:38:58.654{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17025-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221543Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:01.458{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-33525-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221544Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:02.869{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-42238-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221545Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:04.110{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-51769-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221546Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:05.470{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-1405-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221547Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:06.778{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-10993-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221548Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:07.896{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-19435-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221549Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:09.058{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-27254-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221551Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:10.217{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35752-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221550Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:10.059{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in59525-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185710Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:39:09.652{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in16459-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221552Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:11.460{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44202-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221553Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:12.604{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-52478-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221554Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:13.796{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-1934-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221555Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:14.922{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-10458-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221556Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:16.153{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17324-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221558Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:17.760{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-28267-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221557Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:17.519{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk12919-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185711Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:39:17.428{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk13067-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185712Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:39:18.732{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-22428-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221560Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:19.134{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-22399-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221559Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:19.019{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-36200-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221562Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:21.500{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53314-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221561Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:20.285{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44858-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221563Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:22.630{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2974-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221564Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:23.810{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-10876-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221565Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:25.049{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-19423-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221566Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:26.216{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-28034-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221567Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:27.956{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-37622-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221568Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:29.326{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-46349-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221569Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:30.535{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-55321-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221570Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:31.715{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-4380-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221571Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:32.996{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-13107-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221572Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:34.239{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-21912-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221573Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:35.663{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-31189-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221574Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:36.955{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40751-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000185732Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.747{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185731Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.747{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185730Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.747{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185729Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.747{E74F01E8-8FBD-6086-0B00-00000000BA01}5844704C:\Windows\system32\lsass.exe{E74F01E8-8FBA-6086-0100-00000000BA01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 10341000x8000000000000000185728Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185727Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185726Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185725Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185724Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185723Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185722Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185721Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185720Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185719Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185718Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185717Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185716Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185715Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185714Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:39:41.638{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000185713Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:39:37.669{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in57183-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221576Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:38.084{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in11863-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221575Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:38.069{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-48942-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221577Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:39.259{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57613-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221578Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:40.760{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-7412-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221579Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:42.009{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-16229-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221580Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:43.218{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-24642-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221581Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:44.464{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-33248-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221582Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:45.924{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-41953-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221583Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:47.204{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-50740-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221584Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:48.380{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-59589-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221585Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:49.560{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-8661-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221586Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:50.834{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17127-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221587Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:52.121{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-25893-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185733Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:39:52.998{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk14858-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221589Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:53.267{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-34397-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221588Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:53.212{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk14742-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221590Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:54.464{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-42464-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221591Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:55.878{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-51286-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221592Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:57.121{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-1209-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221593Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:58.295{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9765-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221594Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:39:59.496{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18346-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000185736Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:40:03.388{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1500-00000000BA01}1156C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185735Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:40:03.388{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1500-00000000BA01}1156C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185734Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:40:03.388{E74F01E8-8FBF-6086-0C00-00000000BA01}7762152C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1500-00000000BA01}1156C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221595Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:00.777{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-25839-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221596Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:02.026{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35859-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221597Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:03.143{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-43830-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221598Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:04.954{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53364-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221600Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:06.303{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-3320-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221599Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:06.082{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in26029-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185737Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:40:05.679{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in59212-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221601Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:07.579{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-12948-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221602Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:08.743{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-20805-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221603Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:09.897{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-29071-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221605Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:12.312{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-45417-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221604Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:11.180{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-36736-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221606Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:13.480{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53392-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221607Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:14.630{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2973-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221608Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:16.167{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11190-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221609Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:17.315{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-20941-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221610Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:18.680{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-29486-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221611Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:20.181{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-39082-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221612Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:21.316{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-48362-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221613Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:23.039{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57486-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221615Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:25.258{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk13421-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221614Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:24.552{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-8492-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221616Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:25.817{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17718-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221617Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:27.518{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-29019-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185738Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:40:27.977{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk13512-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221618Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:28.647{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-37371-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221619Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:29.815{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44957-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221620Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:31.471{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-55798-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221621Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:32.608{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-4905-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221622Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:34.071{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in51734-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185739Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:40:33.650{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in22693-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221623Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:34.444{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-13865-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221624Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:35.846{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-23582-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221625Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:36.994{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-32327-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221627Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:39.995{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-50647-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221626Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:38.429{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40877-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221628Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:41.296{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-1548-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221629Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:42.411{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-10054-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221630Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:43.720{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17907-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221631Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:44.862{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-26652-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221632Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:46.234{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35015-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000221668Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221667Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221666Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221665Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221664Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221663Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221662Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221661Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221660Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221659Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221658Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221657Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221656Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221655Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221654Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221653Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221652Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221651Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221650Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221649Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221648Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221647Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221646Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221645Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221644Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221643Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221642Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221641Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221640Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221639Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221638Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221637Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221636Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221635Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221634Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221633Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:40:50.843{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221670Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:48.906{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53448-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221669Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:47.668{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44098-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221671Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:50.050{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2648-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221672Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:51.926{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-12420-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221673Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:53.327{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-20499-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221674Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:54.923{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-32053-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221675Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:56.036{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40002-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185740Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:40:56.495{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk12169-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221677Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:57.175{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-47670-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221676Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:56.684{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk11965-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221678Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:40:58.681{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-56220-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221679Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:00.020{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-4928-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185741Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:41:01.600{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in23178-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221680Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:01.239{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-14077-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221681Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:02.017{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in38067-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221682Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:02.916{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-23192-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221683Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:04.264{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-31801-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221684Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:05.515{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-41267-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221685Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:06.932{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-51307-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221687Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:09.648{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9120-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221686Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:08.108{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-58247-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221688Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:11.071{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18866-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221689Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:12.221{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-27732-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221690Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:13.352{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-36547-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221691Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:14.679{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44284-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221693Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:17.130{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2923-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221692Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:15.994{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53179-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221694Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:18.513{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-12660-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221705Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:19.677{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-20246-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 13241300x8000000000000000221704Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000221703Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x09e4839b) 13241300x8000000000000000221702Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c01-0xe2d08e6a) 13241300x8000000000000000221701Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0a-0x4494f66a) 13241300x8000000000000000221700Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c12-0xa6595e6a) 13241300x8000000000000000221699Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000221698Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x09e4839b) 13241300x8000000000000000221697Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c01-0xe2d08e6a) 13241300x8000000000000000221696Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0a-0x4494f66a) 13241300x8000000000000000221695Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:23.333{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c12-0xa6595e6a) 354300x8000000000000000221706Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:20.966{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-29323-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221707Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:22.847{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-39032-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221708Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:24.383{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-48866-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221709Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:25.556{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-58047-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221711Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:27.071{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk8804-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221710Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:26.706{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-7229-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185742Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:41:27.078{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk9245-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221713Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:29.347{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-24208-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221712Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:28.013{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-15669-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185743Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:41:29.615{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in20102-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221715Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:30.496{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-33120-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221714Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:30.021{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in28147-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221716Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:31.948{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-43301-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221717Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:34.495{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-56210-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221718Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:35.758{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-7101-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221719Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:37.344{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18347-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221721Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:40.057{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-32357-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 13241300x8000000000000000221720Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:41:43.739{4C77B871-9763-6086-1400-00000000BB01}1028C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d73c0a-0x5105d134) 354300x8000000000000000221722Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:41.241{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-41894-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221723Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:42.401{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-50360-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221724Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:43.685{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-58301-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221726Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:46.441{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-16936-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221725Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:45.029{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-7479-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221727Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:48.449{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-29240-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221728Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:49.978{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40324-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221729Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:51.151{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-49325-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221730Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:52.525{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-58000-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221732Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:55.743{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17391-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221731Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:54.266{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-8680-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221734Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:57.656{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk6121-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221733Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:57.189{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-27062-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221736Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:58.580{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-36696-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 13241300x8000000000000000185748Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:02.391{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\BD98497A-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_BD98497A-0000-0000-0000-100000000000.XML 13241300x8000000000000000185747Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:02.376{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\4FA15643-EFBD-40F1-AD20-B67AEE8B2612\Config SourceDWORD (0x00000001) 13241300x8000000000000000185746Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:02.376{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\4FA15643-EFBD-40F1-AD20-B67AEE8B2612\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_4FA15643-EFBD-40F1-AD20-B67AEE8B2612.XML 354300x8000000000000000185745Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:41:57.672{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in18846-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185744Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:41:57.591{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk6562-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221735Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:58.096{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in58325-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221737Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:41:59.754{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-45086-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221738Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:00.921{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53842-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221739Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:02.242{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2224-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221740Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:03.529{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11587-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221741Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:05.468{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-23837-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221742Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:06.717{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-33380-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221743Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:08.168{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-43777-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221744Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:09.740{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-52551-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185749Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:42:10.263{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.2.147-51091-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221745Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:11.043{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-2357-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221746Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:12.323{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11013-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221747Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:13.857{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-19992-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221748Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:15.082{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-28899-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221749Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:16.504{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-38032-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221750Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:17.785{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-48473-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221751Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:18.925{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-56865-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221752Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:20.553{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-6465-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221756Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:22.397{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17086-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000221755Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:25.333{4C77B871-9762-6086-0C00-00000000BB01}6882616C:\Windows\system32\svchost.exe{4C77B871-9763-6086-1300-00000000BB01}316C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221754Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:25.333{4C77B871-9762-6086-0C00-00000000BB01}6882616C:\Windows\system32\svchost.exe{4C77B871-9763-6086-1300-00000000BB01}316C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221753Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:25.333{4C77B871-9762-6086-0C00-00000000BB01}6882616C:\Windows\system32\svchost.exe{4C77B871-9763-6086-1300-00000000BB01}316C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221757Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:23.882{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-26738-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221760Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:26.567{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-45571-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221759Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:26.107{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in19086-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221758Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:25.203{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-36242-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221762Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:27.808{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-54998-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221761Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:27.703{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk2959-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185751Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:42:27.393{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk3089-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185750Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:42:25.707{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in27069-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221763Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:29.156{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-5496-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221764Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:30.315{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-13334-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221765Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:32.232{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-23556-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221766Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:33.558{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-33734-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221767Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:34.966{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-42889-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221768Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:36.237{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53111-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221769Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:38.649{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-6286-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000185753Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:42:43.144{E74F01E8-8FC0-6086-1600-00000000BA01}11921448C:\Windows\system32\svchost.exe{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185752Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:42:43.144{E74F01E8-8FC0-6086-1600-00000000BA01}11921448C:\Windows\system32\svchost.exe{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221770Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:39.997{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-15849-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221771Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:41.148{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-24302-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 13241300x8000000000000000185763Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000185762Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a03a90e) 13241300x8000000000000000185761Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c02-0x146257f0) 13241300x8000000000000000185760Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0a-0x7626bff0) 13241300x8000000000000000185759Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c12-0xd7eb27f0) 13241300x8000000000000000185758Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000185757Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a03a90e) 13241300x8000000000000000185756Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c02-0x146257f0) 13241300x8000000000000000185755Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0a-0x7626bff0) 13241300x8000000000000000185754Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:42:47.956{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c12-0xd7eb27f0) 354300x8000000000000000221772Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:42.480{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-32554-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221773Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:43.674{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40807-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221774Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:45.337{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-49942-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000221811Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221810Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221809Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221808Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221807Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221806Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221805Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221804Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221803Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221802Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221801Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221800Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221799Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221798Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221797Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221796Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221795Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221794Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221793Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221792Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221791Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221790Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221789Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221788Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221787Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221786Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221785Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221784Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221783Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221782Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221781Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221780Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221779Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221778Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221777Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221776Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:42:51.864{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221775Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:47.066{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-59632-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221812Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:48.328{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9944-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221813Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:49.525{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18280-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221814Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:51.170{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-28361-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185764Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:42:51.628{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-36420-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221816Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:52.564{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-37220-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221815Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:52.006{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-36363-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221818Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:54.127{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in4750-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221817Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:53.793{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-46660-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221819Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:54.972{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-55381-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185765Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:42:53.714{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in1889-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221820Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:56.392{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-5066-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221821Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:57.540{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk13888-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221822Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:58.010{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-15254-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185766Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:42:57.464{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk14294-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221823Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:42:59.409{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-25723-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221824Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:00.618{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-34059-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221825Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:01.900{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-42830-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221826Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:03.161{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-51596-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221828Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:05.611{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-10041-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221827Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:04.317{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-59854-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221829Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:07.138{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18576-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221830Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:08.432{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-26737-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221831Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:10.133{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-36510-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221832Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:12.190{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-46723-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221833Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:13.805{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57216-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221834Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:15.003{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-7371-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221835Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:16.156{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-15970-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221836Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:17.316{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-24055-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221837Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:18.535{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-31661-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221838Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:19.691{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40245-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221839Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:20.873{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-48978-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185767Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:43:21.701{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in36069-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221841Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:22.171{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-58247-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221840Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:22.126{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in20391-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221842Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:23.987{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9718-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221843Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:25.231{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-19338-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185768Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:43:26.216{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk9743-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221845Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:26.337{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-27986-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221844Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:26.281{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk9620-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221846Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:27.492{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35979-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221847Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:28.671{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44236-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221848Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:30.165{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-54136-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221849Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:31.332{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-3519-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221850Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:32.444{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11993-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221851Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:34.107{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-21172-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221853Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:36.511{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-39350-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221852Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:35.386{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-30967-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221854Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:37.717{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-47905-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221855Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:39.400{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57779-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221856Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:40.579{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-8613-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221857Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:41.859{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-16977-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221858Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:43.126{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-26387-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221859Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:44.269{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-34629-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221861Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:46.648{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-51376-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221860Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:45.517{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-43011-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221862Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:48.034{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-59848-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221864Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:49.677{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk13705-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221863Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:49.536{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9758-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185770Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:43:49.761{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in61384-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185769Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:43:49.415{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk13864-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221865Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:50.171{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in61818-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221867Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:51.919{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-27036-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221866Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:50.708{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18558-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221868Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:53.061{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35452-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221869Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:54.718{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-46083-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221871Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:57.066{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-3991-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221870Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:55.875{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-54747-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221872Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:58.264{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-12277-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221873Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:43:59.441{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-21360-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221874Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:01.589{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-32623-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221875Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:02.731{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-40980-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221877Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:05.160{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57984-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221876Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:03.955{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-49272-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221878Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:06.738{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-9976-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221879Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:07.926{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-18148-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221881Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:10.333{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35385-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221880Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:09.069{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-26649-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221882Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:11.679{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-45031-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221883Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:13.236{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-54109-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221884Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:14.537{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-3977-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221885Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:15.641{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11808-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221886Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:16.836{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-20217-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185771Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:44:17.761{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in5757-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221888Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:18.204{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in31786-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221887Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:18.028{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-28716-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221889Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:19.390{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-38582-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221891Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:21.765{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-54792-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221890Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:20.581{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-46463-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221892Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:22.847{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-4859-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221893Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:24.752{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-15078-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221894Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:26.095{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-24974-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185772Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:44:26.994{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk6697-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221896Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:27.698{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-34794-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221895Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:27.412{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk6627-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221897Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:28.939{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-44790-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221898Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:30.030{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-53581-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221899Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:31.845{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-4347-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221900Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:33.343{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-14344-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185773Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:44:34.460{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse106.120.139.1818.139.120.106.static.bjtelecom.net55032-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221901Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:34.820{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-23391-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221902Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:36.110{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-32841-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000185792Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.900{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185791Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.900{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185790Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.900{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185789Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.884{E74F01E8-8FBD-6086-0B00-00000000BA01}5844412C:\Windows\system32\lsass.exe{E74F01E8-8FBA-6086-0100-00000000BA01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 10341000x8000000000000000185788Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185787Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185786Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185785Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185784Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185783Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185782Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185781Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185780Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185779Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185778Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185777Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185776Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185775Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185774Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:44:41.775{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1400-00000000BA01}1044C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221903Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:37.191{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-42220-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221904Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:38.911{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-50731-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221905Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:40.179{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-59546-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221906Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:41.853{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-11033-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221907Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:43.158{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-21279-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221908Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:44.253{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-30490-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185793Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:44:43.848{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk10370-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221910Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:45.558{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-38704-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221909Microsoft-Windows-Sysmon/Operationalproject-london-hostWinRM12021-04-28 08:44:45.393{4C77B871-975F-6086-0100-00000000BB01}4SystemNT AUTHORITY\SYSTEMtcpfalsefalse162.142.125.53scanner-05.ch1.censys-scanner.com45154-false10.0.1.15project-london-host.eu-west-2.compute.internal5985- 354300x8000000000000000221915Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:47.129{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk10198-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221914Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:46.798{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-47391-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221913Microsoft-Windows-Sysmon/Operationalproject-london-hostWinRM12021-04-28 08:44:46.648{4C77B871-975F-6086-0100-00000000BB01}4SystemNT AUTHORITY\SYSTEMtcpfalsefalse162.142.125.53scanner-05.ch1.censys-scanner.com55126-false10.0.1.15project-london-host.eu-west-2.compute.internal5985- 354300x8000000000000000221912Microsoft-Windows-Sysmon/Operationalproject-london-hostWinRM12021-04-28 08:44:46.477{4C77B871-975F-6086-0100-00000000BB01}4SystemNT AUTHORITY\SYSTEMtcpfalsefalse162.142.125.53scanner-05.ch1.censys-scanner.com50310-false10.0.1.15project-london-host.eu-west-2.compute.internal5985- 354300x8000000000000000221911Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:46.237{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in60815-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185794Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:44:45.825{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in55826-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221916Microsoft-Windows-Sysmon/Operationalproject-london-hostWinRM12021-04-28 08:44:47.819{4C77B871-975F-6086-0100-00000000BB01}4SystemNT AUTHORITY\SYSTEMtcpfalsefalse162.142.125.53scanner-05.ch1.censys-scanner.com33876-false10.0.1.15project-london-host.eu-west-2.compute.internal5985- 10341000x8000000000000000221953Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221952Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221951Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221950Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221949Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221948Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221947Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221946Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221945Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221944Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221943Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221942Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221941Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221940Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221939Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221938Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221937Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221936Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221935Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221934Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221933Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221932Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221931Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221930Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221929Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221928Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221927Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221926Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221925Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221924Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221923Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221922Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221921Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221920Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221919Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221918Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:44:52.873{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221917Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:48.226{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-57738-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221954Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:49.550{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-8602-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221955Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:50.648{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-17988-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221957Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:53.302{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-35535-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221956Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:52.019{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-26288-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221958Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:54.399{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-45185-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221959Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:44:56.279{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.1.80-56401-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000185797Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:45:03.400{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1500-00000000BA01}1156C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185796Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:45:03.400{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1500-00000000BA01}1156C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000185795Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:45:03.400{E74F01E8-8FBF-6086-0C00-00000000BA01}7761072C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1500-00000000BA01}1156C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000185798Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:45:13.072{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk5827-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221960Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:45:14.213{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in27223-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221961Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:45:15.004{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk5071-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185799Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:45:13.780{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in5565-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 10341000x8000000000000000185800Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:45:42.776{E74F01E8-8FBF-6086-0D00-00000000BA01}8322980C:\Windows\system32\svchost.exe{E74F01E8-8FC0-6086-1600-00000000BA01}1192C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000221962Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:45:42.151{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in24410-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185801Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:45:41.759{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in5356-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185802Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:45:42.651{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk2277-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221963Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:45:46.027{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk2238-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000185803Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-2021-04-28 08:46:00.761{E74F01E8-8FBD-6086-0B00-00000000BA01}5844412C:\Windows\system32\lsass.exe{E74F01E8-8FBA-6086-0100-00000000BA01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e 354300x8000000000000000185804Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:46:09.734{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in18629-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221964Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:46:10.136{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in31141-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000221965Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:46:12.767{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk12777-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185805Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:46:12.602{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk12888-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 13241300x8000000000000000221975Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000221974Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x09e9178b) 13241300x8000000000000000221973Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c02-0x95a35d6a) 13241300x8000000000000000221972Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0a-0xf767c56a) 13241300x8000000000000000221971Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c13-0x592c2d6a) 13241300x8000000000000000221970Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000221969Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x09e9178b) 13241300x8000000000000000221968Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c02-0x95a35d6a) 13241300x8000000000000000221967Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0a-0xf767c56a) 13241300x8000000000000000221966Microsoft-Windows-Sysmon/Operationalproject-london-host-SetValue2021-04-28 08:46:23.346{4C77B871-9761-6086-0B00-00000000BB01}588C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c13-0x592c2d6a) 13241300x8000000000000000185806Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:46:40.701{E74F01E8-8FC0-6086-1300-00000000BA01}364C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d73c0b-0x0206933d) 354300x8000000000000000221976Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:46:38.132{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in36943-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185807Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:46:37.710{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in5052-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185808Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:46:43.246{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk9857-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000221977Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:46:43.495{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk9717-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000222013Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222012Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222011Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222010Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222009Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222008Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222007Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222006Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222005Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222004Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222003Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222002Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222001Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222000Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221999Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221998Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221997Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221996Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221995Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221994Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221993Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221992Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221991Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221990Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221989Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221988Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221987Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221986Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221985Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221984Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221983Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221982Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221981Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221980Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221979Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000221978Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:46:53.878{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F14-6087-FC10-00000000BB01}4256C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000185809Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:46:51.165{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse117.2.6.27project-london-dc.iris.local61424-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222014Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:46:57.125{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-24833-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 13241300x8000000000000000185812Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:04.263{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\BD98497A-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_BD98497A-0000-0000-0000-100000000000.XML 13241300x8000000000000000185811Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:04.263{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\4FA15643-EFBD-40F1-AD20-B67AEE8B2612\Config SourceDWORD (0x00000001) 13241300x8000000000000000185810Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:04.263{E74F01E8-8FCD-6086-2400-00000000BA01}2244C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\4FA15643-EFBD-40F1-AD20-B67AEE8B2612\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_4FA15643-EFBD-40F1-AD20-B67AEE8B2612.XML 354300x8000000000000000222015Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:47:05.823{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-37191-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185814Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:47:05.712{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in10450-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185813Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:47:05.420{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse45.155.205.159-37213-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222016Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:47:06.119{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in10251-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185815Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:47:16.677{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk7741-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222017Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:47:20.041{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk7707-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000222020Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:47:25.348{4C77B871-9762-6086-0C00-00000000BB01}6882616C:\Windows\system32\svchost.exe{4C77B871-9763-6086-1300-00000000BB01}316C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222019Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:47:25.348{4C77B871-9762-6086-0C00-00000000BB01}6882616C:\Windows\system32\svchost.exe{4C77B871-9763-6086-1300-00000000BB01}316C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222018Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:47:25.348{4C77B871-9762-6086-0C00-00000000BB01}6882616C:\Windows\system32\svchost.exe{4C77B871-9763-6086-1300-00000000BB01}316C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 354300x8000000000000000185816Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:47:33.855{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in35697-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222021Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:47:34.271{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in58478-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 13241300x8000000000000000185826Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000185825Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a083cfe) 13241300x8000000000000000185824Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c02-0xc73526f0) 13241300x8000000000000000185823Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0b-0x28f98ef0) 13241300x8000000000000000185822Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c13-0x8abdf6f0) 13241300x8000000000000000185821Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006) 13241300x8000000000000000185820Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a083cfe) 13241300x8000000000000000185819Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d73c02-0xc73526f0) 13241300x8000000000000000185818Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d73c0b-0x28f98ef0) 13241300x8000000000000000185817Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.local-SetValue2021-04-28 08:47:47.967{E74F01E8-8FBD-6086-0B00-00000000BA01}584C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d73c13-0x8abdf6f0) 354300x8000000000000000222022Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:47:49.189{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk5788-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185828Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:47:48.902{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk5855-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185827Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:47:48.627{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse185.202.2.147-32366-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222023Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:48:02.237{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in10186-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185829Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:48:01.830{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in14825-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222024Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:48:23.648{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk5551-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 354300x8000000000000000185830Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:48:26.297{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse82.102.13.66h82-102-13-66.host.redstation.co.uk5612-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000185831Microsoft-Windows-Sysmon/Operationalproject-london-dc.iris.localRDP2021-04-28 08:48:30.008{E74F01E8-8FC0-6086-0F00-00000000BA01}968C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in61612-false10.0.1.14project-london-dc.iris.local3389ms-wbt-server 354300x8000000000000000222025Microsoft-Windows-Sysmon/Operationalproject-london-hostRDP2021-04-28 08:48:30.419{4C77B871-9762-6086-1000-00000000BB01}888C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsefalse122.186.14.34nsg-corporate-34.14.186.122.airtel.in17577-false10.0.1.15project-london-host.eu-west-2.compute.internal3389ms-wbt-server 10341000x8000000000000000222061Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222060Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222059Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222058Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222057Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222056Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222055Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222054Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F13-6087-FB10-00000000BB01}3796C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222053Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222052Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222051Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222050Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222049Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222048Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222047Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222046Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222045Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222044Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222043Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222042Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222041Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222040Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\system32\svchost.exe{4C77B871-1F0D-6087-EB10-00000000BB01}2912C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781 10341000x8000000000000000222039Microsoft-Windows-Sysmon/Operationalproject-london-host-2021-04-28 08:48:54.893{4C77B871-9762-6086-0D00-00000000BB01}740768C:\Windows\sy